База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Средняя CVSS 4.8

CVE-2026-21625

РасширениеStackideas Easydiscuss
Разработчикstackideas

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

16.01.2026 Активна
Критическая CVSS 9.4

CVE-2026-21624

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21623

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Средняя CVSS 5.4

CVE-2025-55758

РасширениеJDownloads
Разработчикjdownloads

Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.

28.10.2025
Средняя CVSS 6.1

CVE-2025-55757

РасширениеVirtueMart
Разработчикgithub

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

25.10.2025
Критическая CVSS 9.3

CVE-2025-40636

Разработчикincibe.es

SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoi…

03.10.2025
Высокая CVSS 8.5

CVE-2025-54301

РасширениеQuantum Manager
Разработчикnorrnext

A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.

25.08.2025
Высокая CVSS 8.5

CVE-2025-54300

РасширениеQuantum Manager
Разработчикnorrnext

A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.

25.08.2025
Высокая CVSS 8.7

CVE-2025-54475

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

15.08.2025
Высокая CVSS 8.5

CVE-2025-54474

РасширениеDJ-Classifieds
Разработчикdj-extensions

A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

15.08.2025
Критическая CVSS 9.2

CVE-2025-54473

РасширениеPhoca Commander
РазработчикPhoca

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

15.08.2025
Критическая CVSS 9.4

CVE-2025-54299

РасширениеNo Boss Testimonials
Разработчикnobossextensions

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.4

CVE-2025-54298

РасширениеCommentBox
Разработчикfirecoders

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

28.07.2025
Высокая CVSS 7.0

CVE-2025-54297

РасширениеCComment
Разработчикcompojoom

A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.

23.07.2025
Высокая CVSS 7.0

CVE-2025-54296

РасширениеProFiles
Разработчикmooj

A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.

23.07.2025
Средняя CVSS 5.1

CVE-2025-54295

РасширениеDJ-Reviews
Разработчикdj-extensions

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

23.07.2025
Критическая CVSS 9.3

CVE-2025-54294

РасширениеKomento
Разработчикstackideas

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

23.07.2025
Высокая CVSS 8.5

CVE-2025-50127

РасширениеDJ-Flyer
Разработчикdj-extensions

A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

23.07.2025