База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Средняя CVSS 4.8

CVE-2025-27444

РасширениеRsjoomla Rsform\!pro
Разработчикrsjoomla

A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is r…

04.06.2025
Низкая CVSS 3.8

CVE-2025-25228

РасширениеVirtuemart Virtuemart
Разработчикgithub

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

21.04.2025
Средняя CVSS 5.3

CVE-2025-2714

РасширениеJoomlaux Jux Real Estate
Разработчикvuldb

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /extensions/realestate/index.…

24.03.2025
Средняя CVSS 6.5

CVE-2025-25225

РасширениеHikashop Hikashop
Разработчикgithub

A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Per…

15.03.2025
Средняя CVSS 5.3

CVE-2025-2127

РасширениеJoomlaux Jux Real Estate
Разработчикvuldb

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/pr…

09.03.2025
Средняя CVSS 5.3

CVE-2025-2126

РасширениеJoomlaux Jux Real Estate
Разработчикvuldb

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/pro…

09.03.2025
Низкая CVSS 2.7

CVE-2025-22212

Разработчикgithub

A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the…

05.03.2025
Низкая CVSS 3.4

CVE-2025-22211

РасширениеWebdesigner-profi Joomshopping
Разработчикgithub

A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country m…

25.02.2025
Высокая CVSS 7.2

CVE-2025-22210

РасширениеHikashop Hikashop
Разработчикgithub

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category mana…

25.02.2025
Средняя CVSS 4.7

CVE-2025-22209

РасширениеJoomsky Js Jobs
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentst…

15.02.2025
Средняя CVSS 4.7

CVE-2025-22208

РасширениеJoomsky Js Jobs
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' p…

15.02.2025
Средняя CVSS 4.7

CVE-2025-22206

РасширениеJoomsky Js Jobs
Разработчикdecrypt.locker

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' param…

04.02.2025
Критическая CVSS 9.8

CVE-2025-22204

РасширениеRegularlabs Sourcerer
Разработчикregularlabs

Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

04.02.2025
Критическая CVSS 9.3

CVE-2024-11145

Разработчикgithub

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! applicati…

26.11.2024
Средняя CVSS 5.4

CVE-2024-40746

РасширениеHikashop Hikashop
Разработчикhikashop

A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a m…

21.10.2024