Каталог CVE

Joomla 3

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 51

Joomla 3
Критическая CVSS 9.1

CVE-2021-23127

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.

04.03.2021
Средняя CVSS 5.3

CVE-2021-23126

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.

04.03.2021
Средняя CVSS 6.1

CVE-2021-23125

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.

12.01.2021
Средняя CVSS 6.1

CVE-2021-23124

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

12.01.2021
Средняя CVSS 5.3

CVE-2021-23123

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.

12.01.2021
Средняя CVSS 5.3

CVE-2020-35614

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.

28.12.2020
Критическая CVSS 9.8

CVE-2020-35613

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.

28.12.2020
Высокая CVSS 8.8

CVE-2019-14654

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the fi…

05.08.2019
Критическая CVSS 9.8

CVE-2016-1000271

РасширениеDthdevelopment Dt Register
Разработчикpacketstormsecurity

Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This…

04.02.2019
Высокая CVSS 8.8

CVE-2018-8045

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

15.03.2018
Критическая CVSS 9.8

CVE-2017-8917

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

17.05.2017
Средняя CVSS 5.3

CVE-2017-8057

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.

25.04.2017
Средняя CVSS 6.5

CVE-2017-7989

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.

25.04.2017
Средняя CVSS 6.1

CVE-2017-7987

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.

25.04.2017
Средняя CVSS 6.1

CVE-2017-7984

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.

25.04.2017
Критическая CVSS 9.8

CVE-2016-9081

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

23.01.2017
Высокая CVSS 7.3

CVE-2015-8769

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

12.01.2016