База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 5.3

CVE-2020-11889

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.

21.04.2020
Критическая CVSS 9.8

CVE-2020-10243

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.

16.03.2020
Средняя CVSS 6.1

CVE-2020-10242

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.

16.03.2020
Высокая CVSS 8.8

CVE-2020-10241

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

16.03.2020
Средняя CVSS 5.3

CVE-2020-10240

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.

16.03.2020
Высокая CVSS 8.8

CVE-2020-10239

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

16.03.2020
Высокая CVSS 7.5

CVE-2020-10238

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

16.03.2020
Высокая CVSS 7.2

CVE-2015-7342

РасширениеJoobi Jnews
Разработчикlabs.integrity.pt

JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.

09.03.2020
Высокая CVSS 8.8

CVE-2015-7341

РасширениеJoobi Jnews
Разработчикlabs.integrity.pt

JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.

09.03.2020
Высокая CVSS 8.8

CVE-2015-7339

РасширениеJCE
Разработчикlabs.integrity.pt

JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.

09.03.2020
Высокая CVSS 7.2

CVE-2015-7338

РасширениеAcyba Acymailing
Разработчикlabs.integrity.pt

SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.

09.03.2020
Критическая CVSS 9.8

CVE-2011-4908

РасширениеTiny Tinybrowser
Разработчикvulmon

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

12.02.2020
Критическая CVSS 9.8

CVE-2011-4906

РасширениеTiny Tinybrowser
Разработчикdeveloper.joomla

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

12.02.2020
Критическая CVSS 9.8

CVE-2014-8739

Разработчикosvdb

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly S…

08.02.2020