База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.3

CVE-2015-8769

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

12.01.2016
Высокая CVSS 7.5

CVE-2015-8566

РасширениеJoomla Session
Разработчикjoomla

The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values.

16.12.2015
Высокая CVSS 7.5

CVE-2015-8565

РасширениеJoomla Joomla\!
Разработчикjoomla

Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors.

16.12.2015
Высокая CVSS 7.5

CVE-2015-8564

РасширениеJoomla Joomla\!
Разработчикjoomla

Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension…

16.12.2015
Средняя CVSS 6.8

CVE-2015-8563

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of…

16.12.2015
Высокая CVSS 7.5

CVE-2015-8562

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wi…

16.12.2015
Средняя CVSS 5.0

CVE-2015-7899

РасширениеJoomla Joomla\!
Разработчикjoomla

The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.

29.10.2015
Средняя CVSS 5.0

CVE-2015-7859

РасширениеJoomla Joomla\!
Разработчикjoomla

The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.

29.10.2015
Высокая CVSS 7.5

CVE-2015-7858

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.

29.10.2015
Высокая CVSS 7.5

CVE-2015-7857

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arb…

29.10.2015
Высокая CVSS 7.5

CVE-2015-7297

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

29.10.2015
Средняя CVSS 4.3

CVE-2015-6939

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

18.09.2015
Средняя CVSS 4.3

CVE-2015-6919

Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the…

11.09.2015