Каталог CVE

Расширение: Joomla Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 791

Расширение: Joomla Joomla
Высокая CVSS 7.5

CVE-2007-4777

РасширениеJoomla Joomla
Разработчикosvdb

SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive sectio…

10.09.2007
Высокая CVSS 7.5

CVE-2007-4778

РасширениеJoomla Joomla
Разработчикdownloads.securityfocus

Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter pa…

10.09.2007
Средняя CVSS 4.3

CVE-2007-4779

РасширениеJoomla Joomla
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to…

10.09.2007
Средняя CVSS 6.8

CVE-2007-4780

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scrip…

10.09.2007
Средняя CVSS 6.6

CVE-2007-4781

РасширениеJoomla Joomla
Разработчикosvdb

administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the…

10.09.2007
Высокая CVSS 7.5

CVE-2007-4184

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.

08.08.2007
Средняя CVSS 5.0

CVE-2007-4185

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and…

08.08.2007
Высокая CVSS 7.5

CVE-2007-4187

РасширениеJoomla Joomla
Разработчикjoomlacode

Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the…

08.08.2007
Высокая CVSS 9.3

CVE-2007-4188

РасширениеJoomla Joomla\!
Разработчикsecunia

Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.

08.08.2007
Средняя CVSS 4.3

CVE-2007-4189

РасширениеJoomla Joomla\!
Разработчикosvdb

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) c…

08.08.2007
Средняя CVSS 4.3

CVE-2007-4190

РасширениеJoomla Joomla\!
Разработчикosvdb

CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF se…

08.08.2007
Средняя CVSS 6.8

CVE-2007-2199

Разработчикosvdb

PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products includi…

24.04.2007
Высокая CVSS 7.5

CVE-2006-7008

РасширениеJoomla Joomla
Разработчикsecunia

Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-10…

12.02.2007
Высокая CVSS 7.5

CVE-2006-7009

РасширениеJoomla Joomla
Разработчикsecunia

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

12.02.2007
Высокая CVSS 7.5

CVE-2006-7010

РасширениеJoomla Joomla
Разработчикsecunia

The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack…

12.02.2007
Средняя CVSS 6.8

CVE-2007-0373

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter…

19.01.2007
Высокая CVSS 7.5

CVE-2007-0374

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content e…

19.01.2007
Средняя CVSS 5.0

CVE-2007-0375

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/…

19.01.2007