База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 6.1

CVE-2017-7985

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.

25.04.2017
Средняя CVSS 6.1

CVE-2017-7984

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.

25.04.2017
Средняя CVSS 5.3

CVE-2017-7983

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.

25.04.2017
Средняя CVSS 6.1

CVE-2017-5673

РасширениеKunena Kunena
Разработчикfox.ra.it

In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/it…

22.03.2017
Критическая CVSS 9.8

CVE-2016-9081

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

23.01.2017
Критическая CVSS 9.8

CVE-2016-10045

РасширениеPHPMailer before
Разработчикwordpress

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper inte…

30.12.2016
Высокая CVSS 7.5

CVE-2016-9838

РасширениеJoomla Joomla\!
Разработчикjoomla

An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error en…

16.12.2016
Высокая CVSS 7.5

CVE-2016-9837

РасширениеJoomla Joomla\!
Разработчикjoomla

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content articl…

16.12.2016
Критическая CVSS 9.8

CVE-2016-9836

РасширениеJoomla Joomla\!
Разработчикjoomla

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which e…

05.12.2016
Высокая CVSS 8.1

CVE-2016-8870

РасширениеJoomla Joomla\!
Разработчикjoomla

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers…

04.11.2016
Критическая CVSS 9.8

CVE-2016-8869

РасширениеJoomla Joomla\!
Разработчикjoomla

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incor…

04.11.2016