Каталог CVE

Разработчик: packetstormsecurity

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 184

Разработчик: packetstormsecurity
Высокая CVSS 7.5

CVE-2022-23793

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.

30.03.2022
Высокая CVSS 7.5

CVE-2020-23971

РасширениеGmapfp Gmapfp
Разработчикpacketstormsecurity

gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload fil…

01.09.2020
Высокая CVSS 7.5

CVE-2020-23972

РасширениеGmapfp Gmapfp
Разработчикpacketstormsecurity

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of u…

27.08.2020
Критическая CVSS 9.8

CVE-2019-19576

РасширениеVerot Project Verot
Разработчикpacketstormsecurity

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensio…

04.12.2019
Критическая CVSS 9.8

CVE-2019-10945

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root direct…

10.04.2019
Критическая CVSS 9.8

CVE-2016-1000271

РасширениеDthdevelopment Dt Register
Разработчикpacketstormsecurity

Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This…

04.02.2019