База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 8.8

CVE-2018-8045

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

15.03.2018
Средняя CVSS 6.1

CVE-2018-7717

Разработчикdebugtrap

The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated b…

05.03.2018
Высокая CVSS 7.5

CVE-2018-7482

РасширениеJoomlaworks K2
Разработчикexploit-db

The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cm…

28.02.2018
Критическая CVSS 9.8

CVE-2018-7318

РасширениеBelitsoft Checklist
Разработчикexploit-db

SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7315

РасширениеHarmistechnology Ek Rishta
Разработчикexploit-db

SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7314

РасширениеMlwebtechnologies Prayercenter
Разработчикexploit-db

SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7313

РасширениеCwjoomla Cw Tags
Разработчикexploit-db

SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

22.02.2018
Критическая CVSS 9.8

CVE-2018-7180

РасширениеSaxum2003 Astro
Разработчикexploit-db

SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.

17.02.2018
Критическая CVSS 9.8

CVE-2018-7178

РасширениеSaxum2003 Saxum Picker
Разработчикexploit-db

SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.

17.02.2018
Критическая CVSS 9.8

CVE-2018-7177

РасширениеSaxum2003 Numerology
Разработчикexploit-db

SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.

17.02.2018
Критическая CVSS 9.8

CVE-2018-6585

РасширениеTechjoomla Jticketing
Разработчикexploit-db

SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.

17.02.2018