Каталог CVE

Расширение: Joomla Joomla\!

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 575

Расширение: Joomla Joomla\!
Критическая CVSS 9.8

CVE-2018-11325

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install ste…

22.05.2018
Средняя CVSS 5.9

CVE-2018-11324

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session t…

22.05.2018
Высокая CVSS 8.8

CVE-2018-11323

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.

22.05.2018
Высокая CVSS 7.5

CVE-2018-11322

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.

22.05.2018
Средняя CVSS 6.5

CVE-2018-11321

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an un…

22.05.2018
Высокая CVSS 8.8

CVE-2018-8045

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

15.03.2018
Средняя CVSS 6.1

CVE-2018-6380

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6379

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6377

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox

30.01.2018
Критическая CVSS 9.8

CVE-2018-6376

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.

30.01.2018
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Средняя CVSS 4.3

CVE-2017-16633

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

10.11.2017
Критическая CVSS 9.8

CVE-2017-14596

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

20.09.2017
Низкая CVSS 3.7

CVE-2017-14595

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

20.09.2017
Средняя CVSS 6.1

CVE-2015-5608

РасширениеJoomla Joomla\!
Разработчикjoomla

Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

20.09.2017
Высокая CVSS 8.8

CVE-2017-11364

РасширениеJoomla Joomla\!
Разработчикjoomla

The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging C…

02.08.2017
Средняя CVSS 6.1

CVE-2017-11612

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.

26.07.2017
Средняя CVSS 6.1

CVE-2017-9934

РасширениеJoomla Joomla\!
Разработчикjoomla

Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.

17.07.2017