База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Критическая CVSS 9.8

CVE-2018-5975

РасширениеThekrotek Smart Shoutbox
Разработчикexploit-db

SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.

17.02.2018
Критическая CVSS 9.8

CVE-2018-5974

РасширениеAlbonico Simplecalendar
Разработчикexploit-db

SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.

17.02.2018
Критическая CVSS 9.8

CVE-2018-5971

РасширениеOrdasoft Medialibrary
Разработчикexploit-db

SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.

17.02.2018
Критическая CVSS 9.8

CVE-2018-5970

РасширениеTechjoomla Jgive
Разработчикexploit-db

SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter.

17.02.2018
Средняя CVSS 5.4

CVE-2015-3619

РасширениеVirtuemart Virtuemart
Разработчикdev.virtuemart

Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vec…

06.02.2018
Высокая CVSS 7.5

CVE-2018-6610

РасширениеJlike Project Jlike
Разработчикexploit-db

Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.

05.02.2018
Критическая CVSS 9.8

CVE-2018-6609

Разработчикexploit-db

SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.

05.02.2018
Критическая CVSS 9.8

CVE-2018-6605

Разработчикexploit-db

SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

05.02.2018
Критическая CVSS 9.8

CVE-2018-6582

Разработчикexploit-db

SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

05.02.2018
Критическая CVSS 9.8

CVE-2018-6581

РасширениеJoommasters Jms Music
Разработчикexploit-db

SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6580

РасширениеJanguo Jimtawl
Разработчикexploit-db

Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6579

РасширениеJextn Reverse Auction
Разработчикexploit-db

SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6578

РасширениеJextn Je Paypervideo
Разработчикexploit-db

SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6577

РасширениеJextn Membership
Разработчикexploit-db

SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.

02.02.2018
Критическая CVSS 9.8

CVE-2018-6575

РасширениеJextn Classified
Разработчикexploit-db

SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.

02.02.2018
Средняя CVSS 6.1

CVE-2018-6380

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6379

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.

30.01.2018