Каталог CVE

Разработчик: packetstormsecurity

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 184

Разработчик: packetstormsecurity
Средняя CVSS 6.1

CVE-2018-11690

РасширениеBalbooa Gridbox
Разработчикpacketstormsecurity

The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker…

14.06.2018
Высокая CVSS 8.8

CVE-2015-7715

Разработчикpacketstormsecurity

Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for r…

18.10.2017
Высокая CVSS 7.2

CVE-2015-7714

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) cop…

18.10.2017
Высокая CVSS 7.5

CVE-2015-4074

Разработчикpacketstormsecurity

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticke…

20.09.2017
Критическая CVSS 9.8

CVE-2015-4073

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email para…

20.09.2017
Средняя CVSS 5.4

CVE-2015-4072

Разработчикpacketstormsecurity

Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to…

20.09.2017
Средняя CVSS 5.3

CVE-2015-4071

Разработчикpacketstormsecurity

The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/…

18.08.2017
Средняя CVSS 4.3

CVE-2015-6919

Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the…

11.09.2015
Высокая CVSS 7.5

CVE-2015-2562

РасширениеWeb-dorado Ecommerce Wd
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sear…

20.03.2015
Средняя CVSS 5.0

CVE-2014-100009

РасширениеJoomlaskin Js Multi Hotel
Разработчикpacketstormsecurity

The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) func…

13.01.2015
Средняя CVSS 4.3

CVE-2014-100008

РасширениеJoomlaskin Js Multi Hotel
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows rem…

13.01.2015