Каталог CVE

Joomla 3

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 51

Joomla 3
Высокая CVSS 7.5

CVE-2015-8565

РасширениеJoomla Joomla\!
Разработчикjoomla

Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors.

16.12.2015
Высокая CVSS 7.5

CVE-2015-8564

РасширениеJoomla Joomla\!
Разработчикjoomla

Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension…

16.12.2015
Средняя CVSS 6.8

CVE-2015-8563

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of…

16.12.2015
Средняя CVSS 5.0

CVE-2015-7899

РасширениеJoomla Joomla\!
Разработчикjoomla

The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.

29.10.2015
Средняя CVSS 5.0

CVE-2015-7859

РасширениеJoomla Joomla\!
Разработчикjoomla

The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.

29.10.2015
Высокая CVSS 7.5

CVE-2015-7858

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.

29.10.2015
Высокая CVSS 7.5

CVE-2015-7857

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arb…

29.10.2015
Высокая CVSS 7.5

CVE-2015-7297

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

29.10.2015
Средняя CVSS 4.3

CVE-2015-6939

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

18.09.2015
Средняя CVSS 6.8

CVE-2015-5397

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for request…

14.07.2015
Средняя CVSS 4.3

CVE-2014-6631

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x before 3.2.5 and 3.3.x before 3.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vec…

08.10.2014
Средняя CVSS 4.3

CVE-2013-5583

РасширениеJoomla Joomla\!
Разработчикdisse.cting

Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

29.12.2013
Средняя CVSS 5.0

CVE-2013-1455

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable."

13.02.2013
Высокая CVSS 7.5

CVE-2013-1453

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete a…

13.02.2013