База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Критическая CVSS 9.8

CVE-2017-17870

РасширениеJbuildozer Jbuildozer
Разработчикvel.joomla

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Средняя CVSS 4.3

CVE-2017-16633

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

10.11.2017
Критическая CVSS 9.8

CVE-2017-15965

РасширениеNswd Ns Download Shop
Разработчикsecurityfocus

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

29.10.2017
Критическая CVSS 9.8

CVE-2017-15946

РасширениеSelfget Tag Meta
Разработчикsecurityfocus

In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.

28.10.2017
Высокая CVSS 8.8

CVE-2015-7715

Разработчикpacketstormsecurity

Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for r…

18.10.2017
Высокая CVSS 7.2

CVE-2015-7714

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) cop…

18.10.2017
Средняя CVSS 5.9

CVE-2014-9686

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to p…

28.09.2017
Критическая CVSS 9.8

CVE-2017-14596

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

20.09.2017
Низкая CVSS 3.7

CVE-2017-14595

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

20.09.2017
Средняя CVSS 6.1

CVE-2015-5608

РасширениеJoomla Joomla\!
Разработчикjoomla

Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

20.09.2017
Высокая CVSS 7.5

CVE-2015-4074

Разработчикpacketstormsecurity

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticke…

20.09.2017
Критическая CVSS 9.8

CVE-2015-4073

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email para…

20.09.2017
Средняя CVSS 5.4

CVE-2015-4072

Разработчикpacketstormsecurity

Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to…

20.09.2017
Критическая CVSS 9.8

CVE-2013-7429

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

14.09.2017
Высокая CVSS 7.5

CVE-2017-2550

РасширениеKubik-rubik Easy Joomla Backup
Разработчикvapidlabs

Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.

08.09.2017