Каталог CVE

Разработчик: securityfocus

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 137

Разработчик: securityfocus
Средняя CVSS 6.1

CVE-2018-6380

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6379

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.

30.01.2018
Средняя CVSS 6.1

CVE-2018-6377

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox

30.01.2018
Критическая CVSS 9.8

CVE-2018-6376

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.

30.01.2018
Критическая CVSS 9.8

CVE-2017-15965

РасширениеNswd Ns Download Shop
Разработчикsecurityfocus

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

29.10.2017
Критическая CVSS 9.8

CVE-2017-15946

РасширениеSelfget Tag Meta
Разработчикsecurityfocus

In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.

28.10.2017
Критическая CVSS 9.8

CVE-2015-2798

РасширениеWeb-dorado Contact Form Maker
Разработчикsecurityfocus

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

25.07.2017
Высокая CVSS 7.5

CVE-2010-4938

РасширениеJoomla Com Weblinks
Разработчикsecurityfocus

SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to…

09.10.2011
Высокая CVSS 7.5

CVE-2009-4217

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an…

07.12.2009
Высокая CVSS 7.5

CVE-2009-3817

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL…

28.10.2009