База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 8.8

CVE-2017-20262

РасширениеWebkul Ajax Quiz
Разработчикwebkul

Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid pa…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20261

РасширениеWeborange Bargain Product Vm3
Разработчикexploit-db

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20260

РасширениеWeborange Price Alert
Разработчикexploit-db

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the pr…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20259

РасширениеJoomlashack Osdownloads
Разработчикjoomlashack

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter.…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20258

РасширениеExtro Responsive Portfolio
Разработчикextro.media

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code t…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20257

РасширениеJoomplace Quiz Deluxe
Разработчикjoomplace

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20256

РасширениеJoomplace Survey Force Deluxe
Разработчикjoomplace

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invit…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20255

РасширениеJoombooking Jb Visa
Разработчикjoombooking

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20254

РасширениеGegabyte User Bench
Разработчикgegabyte

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the useri…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20253

РасширениеGegabyte My Projects
Разработчикgegabyte

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerA…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20252

РасширениеNextgeneditor Nextgen Editor
Разработчикexploit-db

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send…

19.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48907

РасширениеJCE
Разработчикjoomlacontenteditor

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

05.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2019-25740

Разработчикexploit-db

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send…

04.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25433

Разработчикjoomlaextensions.co.in

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through t…

01.06.2026 Требует внимания
Средняя CVSS 6.9

CVE-2026-48903

Разработчикjoomla

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

26.05.2026 Активна
Высокая CVSS 8.2

CVE-2026-48904

Разработчикjoomla

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

26.05.2026 Требует внимания
Средняя CVSS 6.9

CVE-2026-48905

Разработчикjoomla

Lack of input filtering leads to an XSS vector in the HTML filter code.

26.05.2026 Активна
Средняя CVSS 6.4

CVE-2026-48900

Разработчикjoomla

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

26.05.2026 Активна