База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 6.1

CVE-2018-6377

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox

30.01.2018
Критическая CVSS 9.8

CVE-2018-6376

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.

30.01.2018
Критическая CVSS 9.8

CVE-2018-5985

РасширениеLivecrm Livecrm Saas Cloud
Разработчикexploit-db

SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.

24.01.2018
Критическая CVSS 9.8

CVE-2018-5984

РасширениеTumder Project Tumder
Разработчикexploit-db

SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.

24.01.2018
Критическая CVSS 9.8

CVE-2018-5696

РасширениеIjoomla Ad Agency
Разработчикvulnerability-lab

The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php.

14.01.2018
Средняя CVSS 6.1

CVE-2015-7324

РасширениеStackideas Komento
Разработчикseclists

Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitr…

27.12.2017
Критическая CVSS 9.8

CVE-2017-17875

РасширениеJextn Jextn Faq Pro
Разработчикexploit-db

The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17872

РасширениеJextn Jextn Video Gallery
Разработчикexploit-db

The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17871

Разработчикexploit-db

The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17870

РасширениеJbuildozer Jbuildozer
Разработчикvel.joomla

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Средняя CVSS 4.3

CVE-2017-16633

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

10.11.2017