База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 6.5

CVE-2025-25225

РасширениеHikashop Hikashop
Разработчикgithub

A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Per…

15.03.2025
Средняя CVSS 5.3

CVE-2025-2127

РасширениеJoomlaux Jux Real Estate
Разработчикvuldb

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/pr…

09.03.2025
Средняя CVSS 5.3

CVE-2025-2126

РасширениеJoomlaux Jux Real Estate
Разработчикvuldb

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/pro…

09.03.2025
Низкая CVSS 2.7

CVE-2025-22212

Разработчикgithub

A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the…

05.03.2025
Низкая CVSS 3.4

CVE-2025-22211

РасширениеWebdesigner-profi Joomshopping
Разработчикgithub

A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country m…

25.02.2025
Высокая CVSS 7.2

CVE-2025-22210

РасширениеHikashop Hikashop
Разработчикgithub

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category mana…

25.02.2025
Средняя CVSS 4.7

CVE-2025-22209

РасширениеJoomsky Js Jobs
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentst…

15.02.2025
Средняя CVSS 4.7

CVE-2025-22208

РасширениеJoomsky Js Jobs
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' p…

15.02.2025
Средняя CVSS 4.7

CVE-2025-22206

РасширениеJoomsky Js Jobs
Разработчикdecrypt.locker

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' param…

04.02.2025
Критическая CVSS 9.8

CVE-2025-22204

РасширениеRegularlabs Sourcerer
Разработчикregularlabs

Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

04.02.2025
Критическая CVSS 9.3

CVE-2024-11145

Разработчикgithub

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! applicati…

26.11.2024
Средняя CVSS 5.4

CVE-2024-40746

РасширениеHikashop Hikashop
Разработчикhikashop

A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a m…

21.10.2024
Средняя CVSS 6.3

CVE-2024-5737

Разработчикcert.pl

Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data w…

28.06.2024
Высокая CVSS 8.2

CVE-2024-5736

Разработчикcert.pl

Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This…

28.06.2024