База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Критическая CVSS 9.8

CVE-2019-19576

РасширениеVerot Project Verot
Разработчикpacketstormsecurity

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensio…

04.12.2019
Средняя CVSS 5.3

CVE-2013-6879

РасширениеMiwisoft Mijosearch
Разработчикhtbridge

The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the insta…

22.11.2019
Средняя CVSS 6.1

CVE-2013-6878

РасширениеMiwisoft Mijosearch
Разработчикhtbridge

Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query para…

22.11.2019
Высокая CVSS 8.8

CVE-2014-1214

РасширениеProjoom Smart Flash Header
Разработчикexchange.xforce.ibmcloud

views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest par…

13.11.2019
Средняя CVSS 5.3

CVE-2019-18674

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.

06.11.2019
Высокая CVSS 8.8

CVE-2019-18650

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

06.11.2019
Средняя CVSS 6.1

CVE-2018-10727

РасширениеFabrikar Fabrik
Разработчикgithub

Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrar…

29.10.2019
Средняя CVSS 5.4

CVE-2019-15120

РасширениеKunena Kunena
Разработчикgithub

The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

16.08.2019
Средняя CVSS 5.3

CVE-2019-15028

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.

14.08.2019
Высокая CVSS 8.8

CVE-2019-14654

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the fi…

05.08.2019
Критическая CVSS 9.8

CVE-2018-17386

Разработчикexploit-db

SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

19.06.2019
Критическая CVSS 9.8

CVE-2018-17398

РасширениеArenam Amgallery
Разработчикexploit-db

SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.

19.06.2019
Средняя CVSS 6.1

CVE-2019-12766

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.

11.06.2019