База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Критическая CVSS 9.8

CVE-2019-19846

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

18.12.2019
Критическая CVSS 9.8

CVE-2019-19634

РасширениеVerot Project Verot
Разработчикgithub

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensi…

17.12.2019
Критическая CVSS 9.8

CVE-2019-19576

РасширениеVerot Project Verot
Разработчикpacketstormsecurity

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensio…

04.12.2019
Средняя CVSS 5.3

CVE-2013-6879

РасширениеMiwisoft Mijosearch
Разработчикhtbridge

The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the insta…

22.11.2019
Средняя CVSS 6.1

CVE-2013-6878

РасширениеMiwisoft Mijosearch
Разработчикhtbridge

Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query para…

22.11.2019
Высокая CVSS 8.8

CVE-2014-1214

РасширениеProjoom Smart Flash Header
Разработчикexchange.xforce.ibmcloud

views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest par…

13.11.2019
Средняя CVSS 5.3

CVE-2019-18674

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.

06.11.2019
Высокая CVSS 8.8

CVE-2019-18650

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

06.11.2019
Средняя CVSS 6.1

CVE-2018-10727

РасширениеFabrikar Fabrik
Разработчикgithub

Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrar…

29.10.2019
Средняя CVSS 5.4

CVE-2019-15120

РасширениеKunena Kunena
Разработчикgithub

The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

16.08.2019
Средняя CVSS 5.3

CVE-2019-15028

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.

14.08.2019
Высокая CVSS 8.8

CVE-2019-14654

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the fi…

05.08.2019
Критическая CVSS 9.8

CVE-2018-17386

Разработчикexploit-db

SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

19.06.2019