База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 255

Высокая CVSS 8.7

CVE-2023-54357

Разработчикartio

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function i…

19.06.2026 Требует внимания
Высокая CVSS 8.7

CVE-2019-25762

Разработчикjoomboost

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoin…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2019-25761

Разработчикjoomboost

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id…

19.06.2026 Требует внимания
Средняя CVSS 6.9

CVE-2019-25760

Разработчикjoomtech

Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attacke…

19.06.2026 Активна
Высокая CVSS 7.1

CVE-2019-25759

РасширениеWdmtech Vbizz
Разработчикwdmtech

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid para…

19.06.2026 Требует внимания
Высокая CVSS 8.7

CVE-2019-25758

РасширениеWdmtech Vbizz
Разработчикwdmtech

Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2019-25757

Разработчикwdmtech

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and us…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25756

Разработчикwdmtech

Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid p…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25755

Разработчикwdmtech

Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId p…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25754

Разработчикwdmtech

Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25753

РасширениеWdmtech Vmap
Разработчикwdmtech

Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25752

РасширениеCmsjunkie J-businessdirectory
Разработчикcmsjunkie

Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25751

РасширениеCmsjunkie Classifiedsmanager
Разработчикcmsjunkie

Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25750

Разработчикcmsjunkie

Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2019-25749

РасширениеCmsjunkie J-cruiseportal
Разработчикcmsjunkie

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2019-25748

РасширениеCmsjunkie Jhotelreservation
Разработчикcmsjunkie

Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms p…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20282

РасширениеSoft-php Jcart For Opencart
Разработчикsoft-php

Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the produ…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20281

РасширениеJoomlaboat Extra Search
Разработчикjoomlaboat

Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establena…

19.06.2026 Требует внимания