База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2015-6513

РасширениеJ2store J2store
Разработчикj2store

Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) man…

18.08.2015
Средняя CVSS 6.8

CVE-2015-5397

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for request…

14.07.2015
Высокая CVSS 7.5

CVE-2015-4654

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent.

18.06.2015
Низкая CVSS 2.1

CVE-2014-8607

РасширениеXcloner Xcloner
Разработчикvapid.dhs

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the p…

10.06.2015
Средняя CVSS 4.0

CVE-2014-8606

РасширениеXcloner Xcloner
Разработчикvapid.dhs

Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file paramet…

10.06.2015
Средняя CVSS 5.0

CVE-2014-8605

РасширениеXcloner Xcloner
Разработчикvapid.dhs

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote att…

10.06.2015
Средняя CVSS 5.0

CVE-2014-8604

РасширениеXcloner Xcloner
Разработчикvapid.dhs

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensit…

10.06.2015
Средняя CVSS 6.5

CVE-2014-8603

РасширениеXcloner Xcloner
Разработчикvapid.dhs

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name whe…

10.06.2015
Высокая CVSS 7.5

CVE-2015-2562

РасширениеWeb-dorado Ecommerce Wd
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sear…

20.03.2015
Средняя CVSS 4.3

CVE-2015-1478

РасширениеCmsjunkie J-classifiedsmanager
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to…

04.02.2015
Высокая CVSS 7.5

CVE-2015-1477

РасширениеCmsjunkie J-classifiedsmanager
Разработчикosvdb

SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to cl…

04.02.2015
Средняя CVSS 5.0

CVE-2014-100009

РасширениеJoomlaskin Js Multi Hotel
Разработчикpacketstormsecurity

The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) func…

13.01.2015
Средняя CVSS 4.3

CVE-2014-100008

РасширениеJoomlaskin Js Multi Hotel
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows rem…

13.01.2015
Средняя CVSS 4.3

CVE-2013-7419

РасширениеJoomlaskin Js Multi Hotel
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attacke…

09.01.2015
Средняя CVSS 4.3

CVE-2014-9103

РасширениеKunena Kunena
Разработчикpacketstormsecurity

Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of…

26.11.2014
Средняя CVSS 6.5

CVE-2014-9102

РасширениеKunena Kunena
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array pa…

26.11.2014
Высокая CVSS 7.5

CVE-2014-7228

РасширениеJoomla Joomla\!
Разработчикjoomla

Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Profess…

03.11.2014
Средняя CVSS 4.3

CVE-2014-3863

Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a f…

20.10.2014