База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 5.4

CVE-2025-55758

РасширениеJDownloads
Разработчикjdownloads

Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.

28.10.2025
Средняя CVSS 6.1

CVE-2025-55757

РасширениеVirtueMart
Разработчикgithub

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

25.10.2025
Критическая CVSS 9.3

CVE-2025-40636

Разработчикincibe.es

SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoi…

03.10.2025
Высокая CVSS 8.5

CVE-2025-54301

РасширениеQuantum Manager
Разработчикnorrnext

A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.

25.08.2025
Высокая CVSS 8.5

CVE-2025-54300

РасширениеQuantum Manager
Разработчикnorrnext

A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.

25.08.2025
Высокая CVSS 8.7

CVE-2025-54475

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

15.08.2025
Высокая CVSS 8.5

CVE-2025-54474

РасширениеDJ-Classifieds
Разработчикdj-extensions

A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

15.08.2025
Критическая CVSS 9.2

CVE-2025-54473

РасширениеPhoca Commander
РазработчикPhoca

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

15.08.2025
Критическая CVSS 9.4

CVE-2025-54299

РасширениеNo Boss Testimonials
Разработчикnobossextensions

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.4

CVE-2025-54298

РасширениеCommentBox
Разработчикfirecoders

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

28.07.2025
Высокая CVSS 7.0

CVE-2025-54297

РасширениеCComment
Разработчикcompojoom

A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.

23.07.2025
Высокая CVSS 7.0

CVE-2025-54296

РасширениеProFiles
Разработчикmooj

A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.

23.07.2025
Средняя CVSS 5.1

CVE-2025-54295

РасширениеDJ-Reviews
Разработчикdj-extensions

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

23.07.2025
Критическая CVSS 9.3

CVE-2025-54294

РасширениеKomento
Разработчикstackideas

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

23.07.2025
Высокая CVSS 8.5

CVE-2025-50127

РасширениеDJ-Flyer
Разработчикdj-extensions

A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

23.07.2025
Средняя CVSS 5.3

CVE-2025-50126

Расширениеthe RSBlog!
Разработчикrsjoomla

A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tag…

18.07.2025
Средняя CVSS 5.1

CVE-2025-50058

Расширениеthe RSDirectory!
Разработчикrsjoomla

A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the re…

18.07.2025
Средняя CVSS 6.9

CVE-2025-50057

РасширениеRSFiles!
Разработчикrsjoomla

A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to service via the search feature.

18.07.2025