База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 169

Критическая CVSS 10.0

CVE-2026-48907

РасширениеJCE
Разработчикjoomlacontenteditor

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

05.06.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-48902

Разработчикjoomla

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

26.05.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-34424

Разработчикpatchstack

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers…

09.04.2026 Требует внимания
Критическая CVSS 9.5

CVE-2026-21627

Разработчикtassos.gr

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functional…

20.02.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21624

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21623

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.3

CVE-2025-40636

Разработчикincibe.es

SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoi…

03.10.2025
Критическая CVSS 9.2

CVE-2025-54473

РасширениеPhoca Commander
РазработчикPhoca

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

15.08.2025
Критическая CVSS 9.4

CVE-2025-54299

РасширениеNo Boss Testimonials
Разработчикnobossextensions

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.4

CVE-2025-54298

РасширениеCommentBox
Разработчикfirecoders

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.3

CVE-2025-54294

РасширениеKomento
Разработчикstackideas

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

23.07.2025
Критическая CVSS 9.8

CVE-2025-26855

РасширениеArticles Calendar
Разработчикjoomcar

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Критическая CVSS 9.8

CVE-2025-26854

РасширениеArticles Good Search
Разработчикjoomcar

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Критическая CVSS 9.3

CVE-2025-49467

РасширениеJEvents component before
Разработчикjevents

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list…

12.06.2025
Критическая CVSS 9.2

CVE-2025-30085

РасширениеRSForm!pro
Разработчикrsjoomla

Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative acces…

11.06.2025
Критическая CVSS 9.8

CVE-2025-22204

РасширениеRegularlabs Sourcerer
Разработчикregularlabs

Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

04.02.2025
Критическая CVSS 9.3

CVE-2024-11145

Разработчикgithub

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! applicati…

26.11.2024