База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 200

Критическая CVSS 9.8

CVE-2017-17870

РасширениеJbuildozer Jbuildozer
Разработчикvel.joomla

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Критическая CVSS 9.8

CVE-2017-15965

РасширениеNswd Ns Download Shop
Разработчикsecurityfocus

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

29.10.2017
Критическая CVSS 9.8

CVE-2017-15946

РасширениеSelfget Tag Meta
Разработчикsecurityfocus

In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.

28.10.2017
Критическая CVSS 9.8

CVE-2017-14596

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

20.09.2017
Критическая CVSS 9.8

CVE-2015-4073

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email para…

20.09.2017
Критическая CVSS 9.8

CVE-2013-7429

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

14.09.2017
Критическая CVSS 9.8

CVE-2015-2798

РасширениеWeb-dorado Contact Form Maker
Разработчикsecurityfocus

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

25.07.2017
Критическая CVSS 9.8

CVE-2017-8917

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

17.05.2017
Критическая CVSS 9.8

CVE-2017-5215

РасширениеCodextrous B2j Contact
Разработчикnavixia

The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechanism, leading to remote code ex…

17.05.2017
Критическая CVSS 9.8

CVE-2016-9081

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

23.01.2017
Критическая CVSS 9.8

CVE-2016-10045

РасширениеPHPMailer before
Разработчикwordpress

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper inte…

30.12.2016
Критическая CVSS 9.8

CVE-2016-9836

РасширениеJoomla Joomla\!
Разработчикjoomla

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which e…

05.12.2016
Критическая CVSS 9.8

CVE-2016-8869

РасширениеJoomla Joomla\!
Разработчикjoomla

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incor…

04.11.2016