Каталог CVE

Расширение: Joomla Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 791

Расширение: Joomla Joomla
Средняя CVSS 5.0

CVE-2008-4764

РасширениеExtplorer Com Extplorer
Разработчикsecurityfocus

Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir para…

28.10.2008
Высокая CVSS 9.0

CVE-2008-4668

РасширениеJoomla Com Imagebrowser
Разработчикsecurityreason

Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot)…

22.10.2008
Высокая CVSS 7.5

CVE-2008-4623

Разработчикsecunia

SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.p…

21.10.2008
Высокая CVSS 7.5

CVE-2008-4617

РасширениеPyxicom Actualite
Разработчикsecurityreason

SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

20.10.2008
Высокая CVSS 7.5

CVE-2008-4105

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecif…

18.09.2008
Средняя CVSS 5.8

CVE-2008-4104

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.

18.09.2008
Средняя CVSS 5.0

CVE-2008-4103

РасширениеJoomla Com Mailto
Разработчикdeveloper.joomla

The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.

18.09.2008
Высокая CVSS 7.5

CVE-2008-4102

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated b…

18.09.2008
Высокая CVSS 7.5

CVE-2008-3498

Разработчикsecunia

SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action…

06.08.2008
Высокая CVSS 10.0

CVE-2008-3225

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."

18.07.2008
Средняя CVSS 5.0

CVE-2008-3226

РасширениеJoomla Joomla
Разработчикjoomla

The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3227

РасширениеJoomla Joomla
Разработчикjoomla

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3228

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-2990

РасширениеJoomla Com Facileforms
Разработчикsecurityreason

PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP…

02.07.2008
Высокая CVSS 7.5

CVE-2008-2676

РасширениеJoomla Com News Portal
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid param…

12.06.2008
Высокая CVSS 7.5

CVE-2008-2628

РасширениеJoomla Joomla
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

10.06.2008
Высокая CVSS 7.5

CVE-2008-2632

РасширениеJoomla Com Acctexp
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subs…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2633

РасширениеJoomla Com Joomradio
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1)…

10.06.2008