Каталог CVE

Расширение: Joomla Joomla\!

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 575

Расширение: Joomla Joomla\!
Высокая CVSS 7.5

CVE-2008-3498

Разработчикsecunia

SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action…

06.08.2008
Средняя CVSS 6.8

CVE-2008-1559

РасширениеBernard Gilly Com Alphacontent
Разработчикsecurityfocus

SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i…

31.03.2008
Высокая CVSS 9.3

CVE-2008-1465

РасширениеDetodas Com Restaurante
Разработчикsecunia

SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i…

24.03.2008
Высокая CVSS 7.5

CVE-2008-0801

РасширениеPaxxgallery Com Paxxgallery
Разработчикsecurityfocus

SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid pa…

15.02.2008
Средняя CVSS 4.3

CVE-2007-5577

РасширениеJoomla Joomla\!
Разработчикjoomlacode

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Nam…

18.10.2007
Высокая CVSS 9.3

CVE-2007-4188

РасширениеJoomla Joomla\!
Разработчикsecunia

Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.

08.08.2007
Средняя CVSS 4.3

CVE-2007-4189

РасширениеJoomla Joomla\!
Разработчикosvdb

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) c…

08.08.2007
Средняя CVSS 4.3

CVE-2007-4190

РасширениеJoomla Joomla\!
Разработчикosvdb

CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF se…

08.08.2007
Средняя CVSS 6.8

CVE-2006-5043

РасширениеJoomlaboard Joomlaboard
Разработчикforum.joomla

Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a U…

27.09.2006
Средняя CVSS 6.8

CVE-2006-5048

Разработчикforum.joomla

Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL…

27.09.2006
Средняя CVSS 6.8

CVE-2006-4468

РасширениеJoomla Joomla\!
Разработчикsecunia

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2)…

31.08.2006
Высокая CVSS 7.5

CVE-2006-4469

РасширениеJoomla Joomla\!
Разработчикsecunia

Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."

31.08.2006
Высокая CVSS 7.5

CVE-2006-4470

РасширениеJoomla Joomla\!
Разработчикsecunia

Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.

31.08.2006
Средняя CVSS 6.5

CVE-2006-4471

РасширениеJoomla Joomla\!
Разработчикsecunia

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.

31.08.2006
Высокая CVSS 7.5

CVE-2006-4472

РасширениеJoomla Joomla\!
Разработчикsecunia

Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_co…

31.08.2006
Средняя CVSS 5.0

CVE-2006-1957

РасширениеJoomla Joomla\!
Разработчикarchives.neohapsis

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with d…

21.04.2006
Средняя CVSS 5.3

CVE-2005-4650

РасширениеJoomla Joomla\!
Разработчикsecunia

Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.

31.12.2005