База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 5.1

CVE-2025-50056

РасширениеRSMail!
Разработчикrsjoomla

A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted param…

18.07.2025
Высокая CVSS 8.6

CVE-2025-49485

Расширениеthe Balbooa Forms
РазработчикНе указан в CVE

A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.

18.07.2025
Высокая CVSS 8.7

CVE-2025-49484

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee app…

18.07.2025
Критическая CVSS 9.8

CVE-2025-26855

РасширениеArticles Calendar
Разработчикjoomcar

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Критическая CVSS 9.8

CVE-2025-26854

РасширениеArticles Good Search
Разработчикjoomcar

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Высокая CVSS 8.6

CVE-2025-49468

Разработчикnobossextensions

A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via…

13.06.2025
Критическая CVSS 9.3

CVE-2025-49467

РасширениеJEvents component before
Разработчикjevents

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list…

12.06.2025
Средняя CVSS 6.7

CVE-2025-32466

РасширениеRSMediaGallery!
Разработчикrsjoomla

A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properl…

11.06.2025
Высокая CVSS 8.5

CVE-2025-32465

РасширениеRSTickets!
Разработчикrsjoomla

A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.

11.06.2025
Критическая CVSS 9.2

CVE-2025-30085

РасширениеRSForm!pro
Разработчикrsjoomla

Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative acces…

11.06.2025
Средняя CVSS 6.1

CVE-2025-30084

РасширениеRsjoomla Rsmail\!
Разработчикrsjoomla

A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanit…

05.06.2025
Средняя CVSS 6.5

CVE-2025-27754

РасширениеRsjoomla Rsform\!blog
Разработчикrsjoomla

A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's reso…

05.06.2025
Средняя CVSS 6.5

CVE-2025-27753

РасширениеRSMediaGallery
Разработчикrsjoomla

A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the…

05.06.2025
Средняя CVSS 5.4

CVE-2025-27445

РасширениеRSFirewall
Разработчикrsjoomla

A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root…

05.06.2025
Средняя CVSS 4.8

CVE-2025-27444

РасширениеRsjoomla Rsform\!pro
Разработчикrsjoomla

A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is r…

04.06.2025
Низкая CVSS 3.8

CVE-2025-25228

РасширениеVirtuemart Virtuemart
Разработчикgithub

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

21.04.2025
Средняя CVSS 5.3

CVE-2025-2714

РасширениеJoomlaux Jux Real Estate
Разработчикvuldb

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /extensions/realestate/index.…

24.03.2025