Каталог CVE

Расширение: Joomla Joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 791

Расширение: Joomla Joomla
Высокая CVSS 7.5

CVE-2007-0387

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid…

19.01.2007
Средняя CVSS 4.3

CVE-2006-6832

РасширениеJoomla Joomla
Разработчикforge.joomla

Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the…

31.12.2006
Высокая CVSS 7.5

CVE-2006-6833

РасширениеJoomla Joomla
Разработчикjvn.jp

com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

31.12.2006
Средняя CVSS 6.8

CVE-2006-6834

РасширениеJoomla Joomla
Разработчикjvn.jp

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

31.12.2006
Средняя CVSS 6.8

CVE-2006-5043

РасширениеJoomlaboard Joomlaboard
Разработчикforum.joomla

Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a U…

27.09.2006
Средняя CVSS 6.8

CVE-2006-5048

Разработчикforum.joomla

Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL…

27.09.2006
Высокая CVSS 10.0

CVE-2006-4996

РасширениеJoomla Joomlalib
Разработчикforge.joomla

Unspecified vulnerability in JoomlaLib (com_joomlalib) before 1.2.2 for Joomla! allows remote attackers to have an unknown impact, related to "Joomla globals hacked by script kiddies."

26.09.2006
Средняя CVSS 5.0

CVE-2006-4466

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote at…

31.08.2006
Средняя CVSS 6.8

CVE-2006-4468

РасширениеJoomla Joomla\!
Разработчикsecunia

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2)…

31.08.2006
Высокая CVSS 7.5

CVE-2006-4469

РасширениеJoomla Joomla\!
Разработчикsecunia

Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."

31.08.2006
Высокая CVSS 7.5

CVE-2006-4470

РасширениеJoomla Joomla\!
Разработчикsecunia

Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.

31.08.2006
Средняя CVSS 6.5

CVE-2006-4471

РасширениеJoomla Joomla\!
Разработчикsecunia

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.

31.08.2006
Высокая CVSS 7.5

CVE-2006-4472

РасширениеJoomla Joomla\!
Разработчикsecunia

Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_co…

31.08.2006
Средняя CVSS 5.1

CVE-2006-4473

РасширениеJoomla Joomla
Разработчикsecunia

Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.

31.08.2006
Средняя CVSS 6.8

CVE-2006-4474

РасширениеJoomla Joomla
Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Man…

31.08.2006
Высокая CVSS 7.5

CVE-2006-4475

РасширениеJoomla Joomla
Разработчикsecunia

Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.

31.08.2006
Высокая CVSS 7.5

CVE-2006-4476

РасширениеJoomla Joomla
Разработчикsecunia

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead…

31.08.2006
Средняя CVSS 5.8

CVE-2006-3480

РасширениеJoomla Joomla
Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUs…

10.07.2006