Каталог CVE

Расширение: Joomla Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 791

Расширение: Joomla Joomla
Высокая CVSS 7.5

CVE-2013-1453

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete a…

13.02.2013
Средняя CVSS 4.3

CVE-2012-6514

Разработчикhauntit.blogspot

Cross-site scripting (XSS) vulnerability in the nBill (com_nbill) component 2.3.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the message parameter in an…

24.01.2013
Средняя CVSS 5.0

CVE-2012-1599

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a…

03.12.2012
Высокая CVSS 7.5

CVE-2012-1598

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."

03.12.2012
Высокая CVSS 10.0

CVE-2010-5286

РасширениеJoobi Com Jstore
Разработчикpacketstormsecurity

Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot)…

26.11.2012
Высокая CVSS 7.5

CVE-2010-5280

РасширениеJoomla-cbe Com Cbe
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary l…

26.11.2012
Средняя CVSS 4.3

CVE-2012-5827

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors involving "Inadequate protection."

11.11.2012
Средняя CVSS 4.3

CVE-2012-4532

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary…

31.10.2012
Средняя CVSS 4.3

CVE-2012-4531

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

31.10.2012
Средняя CVSS 4.3

CVE-2012-5455

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, rel…

22.10.2012
Средняя CVSS 5.0

CVE-2011-4911

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.

07.10.2012
Средняя CVSS 4.3

CVE-2011-4910

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

07.10.2012
Средняя CVSS 4.3

CVE-2011-4909

РасширениеJoomla Joomla\!
Разработчикarchives.neohapsis

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_…

07.10.2012
Средняя CVSS 4.3

CVE-2012-5232

РасширениеMediafire Mod Quick Form
Разработчикdocs.joomla

Cross-site scripting (XSS) vulnerability in the Quickl Form component for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

01.10.2012
Средняя CVSS 4.3

CVE-2012-1117

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

26.09.2012