База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 255

Высокая CVSS 8.8

CVE-2017-20280

РасширениеMyportfolio Myportfolio
Разработчикexploit-db

Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid paramet…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20279

РасширениеExtensions Joomla Payage
Разработчикexploit-db

Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers ca…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20278

РасширениеJoomboost Joomrecipe
Разработчикexploit-db

Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category par…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20277

РасширениеJoomboost Joomla Joomrecipe
Разработчикjoomboost

Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20276

РасширениеSimbunch Simgenealogy
Разработчикexploit-db

Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type para…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20275

Разработчикexploit-db

Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20274

Разработчикexploit-db

Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id par…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20273

Разработчикexploit-db

Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throu…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20272

Разработчикexploit-db

Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20271

Разработчикexploit-db

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid p…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20270

Разработчикraindropsinfotech

Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userna…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20269

Разработчикterrywcarter

Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20268

Разработчикexploit-db

Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20267

РасширениеJoomla Calendar Planner
Разработчикjoomla

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers ca…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20266

РазработчикJoomShaper

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchwor…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2017-20265

РасширениеPulseextensions Flip Wall
Разработчикpulseextensions

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2017-20264

РасширениеPulseextensions Sponsor Wall
Разработчикpulseextensions

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wal…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20263

РасширениеFocalpointx Focalpoint
Разработчикfocalpointx

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug…

19.06.2026 Требует внимания