База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 180

Средняя CVSS 5.3

CVE-2018-25337

Разработчикexploit-db

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicio…

17.05.2026 Активна
Высокая CVSS 8.8

CVE-2018-25330

Разработчикexploit-db

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST para…

17.05.2026 Требует внимания
Средняя CVSS 6.9

CVE-2018-25327

Разработчикexploit-db

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft mal…

17.05.2026 Активна
Высокая CVSS 7.1

CVE-2020-37226

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2020-37224

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 8.7

CVE-2020-37219

Разработчикfabrikar

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send…

13.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2020-37218

Разработчикexploit-db

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code th…

13.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2021-47930

Разработчикbalbooa

Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Atta…

10.05.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-34424

Разработчикpatchstack

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers…

09.04.2026 Требует внимания
Средняя CVSS 5.1

CVE-2023-54364

Разработчикdemo.hikashop

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54363

Разработчикsolidres

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters incl…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54362

Разработчикdemo.virtuemart

Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attac…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54361

Разработчикthethinkery

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. At…

09.04.2026 Активна
Средняя CVSS 5.1

CVE-2023-54360

Разработчикjlexart

Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can…

09.04.2026 Активна
Критическая CVSS 9.5

CVE-2026-21627

Разработчикtassos.gr

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functional…

20.02.2026 Требует внимания
Средняя CVSS 4.8

CVE-2026-21625

РасширениеStackideas Easydiscuss
Разработчикstackideas

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

16.01.2026 Активна
Критическая CVSS 9.4

CVE-2026-21624

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21623

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания