База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 4.3

CVE-2012-2413

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie paramete…

20.10.2014
Высокая CVSS 7.5

CVE-2014-7984

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving GMail authentication.

08.10.2014
Средняя CVSS 4.3

CVE-2014-7983

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vector…

08.10.2014
Средняя CVSS 4.3

CVE-2014-7982

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

08.10.2014
Высокая CVSS 7.5

CVE-2014-7981

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

08.10.2014
Средняя CVSS 5.0

CVE-2014-7229

РасширениеJoomla Joomla\!
Разработчикjoomla

Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of service via unspecified vectors.

08.10.2014
Высокая CVSS 7.5

CVE-2014-6632

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authenticati…

08.10.2014
Средняя CVSS 4.3

CVE-2014-6631

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x before 3.2.5 and 3.3.x before 3.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vec…

08.10.2014
Высокая CVSS 7.5

CVE-2014-4960

РасширениеJoomlaboat Com Youtubegallery
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to exe…

21.07.2014
Средняя CVSS 4.3

CVE-2013-5956

РасширениеJoomlaboat Com Youtubegallery
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) component 3.4.0 for Joomla! allows remote attackers to inject arbitrary web…

25.04.2014
Низкая CVSS 2.6

CVE-2013-5951

РасширениеExtplorer Extplorer
Разработчикarchives.neohapsis

Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO…

25.03.2014
Средняя CVSS 4.3

CVE-2013-5955

РасширениеPurplebeanie Com Pbbooking
Разработчикpurplebeanie

Cross-site scripting (XSS) vulnerability in manage.php in the PBBooking (com_pbbooking) component 2.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the an a…

19.03.2014
Средняя CVSS 4.3

CVE-2013-5953

РасширениеCodepeople Com Multicalendar
Разработчикcodepeople

Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow…

19.03.2014
Средняя CVSS 4.3

CVE-2013-5952

РасширениеCodologic Com Freichat
Разработчикjoomla

Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or…

19.03.2014
Средняя CVSS 4.3

CVE-2013-1636

РасширениеCaseproof Prettylinks
Разработчикarchives.neohapsis

Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jn…

12.03.2014
Средняя CVSS 4.3

CVE-2013-3933

РасширениеMaxxmarketing Joomshopping
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the use…

11.02.2014
Средняя CVSS 4.3

CVE-2014-1837

РасширениеStackideas Komento
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vector…

30.01.2014
Средняя CVSS 4.3

CVE-2014-0793

РасширениеStackideas Komento
Разработчикstackideas

Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML…

30.01.2014