Каталог CVE

Разработчик: joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 103

Разработчик: joomla
Высокая CVSS 7.5

CVE-2026-48901

Разработчикjoomla

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48898

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Требует внимания
Средняя CVSS 5.3

CVE-2026-48899

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Активна
Средняя CVSS 6.4

CVE-2026-48900

Разработчикjoomla

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

26.05.2026 Активна
Средняя CVSS 5.9

CVE-2026-40384

Разработчикjoomla

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

26.05.2026 Активна
Высокая CVSS 7.5

CVE-2026-40383

Разработчикjoomla

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

26.05.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-35223

Разработчикjoomla

An improper access check allows unauthorized access to com_config webservice endpoints.

26.05.2026 Требует внимания
Средняя CVSS 4.6

CVE-2026-35220

Разработчикjoomla

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-35221

Разработчикjoomla

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-35222

Разработчикjoomla

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-30895

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-25900

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the feed modules.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-25901

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the multilingual associations component.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-30894

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the content history component.

26.05.2026 Активна
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Средняя CVSS 4.3

CVE-2017-16633

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

10.11.2017
Критическая CVSS 9.8

CVE-2017-14596

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

20.09.2017
Низкая CVSS 3.7

CVE-2017-14595

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

20.09.2017