База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 200

Критическая CVSS 9.4

CVE-2026-21623

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.3

CVE-2025-40636

Разработчикincibe.es

SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoi…

03.10.2025
Критическая CVSS 9.2

CVE-2025-54473

РасширениеPhoca Commander
РазработчикPhoca

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

15.08.2025
Критическая CVSS 9.4

CVE-2025-54299

РасширениеNo Boss Testimonials
Разработчикnobossextensions

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.4

CVE-2025-54298

РасширениеCommentBox
Разработчикfirecoders

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

28.07.2025
Критическая CVSS 9.3

CVE-2025-54294

РасширениеKomento
Разработчикstackideas

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

23.07.2025
Критическая CVSS 9.8

CVE-2025-26855

РасширениеArticles Calendar
Разработчикjoomcar

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Критическая CVSS 9.8

CVE-2025-26854

РасширениеArticles Good Search
Разработчикjoomcar

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

18.07.2025
Критическая CVSS 9.3

CVE-2025-49467

РасширениеJEvents component before
Разработчикjevents

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list…

12.06.2025
Критическая CVSS 9.2

CVE-2025-30085

РасширениеRSForm!pro
Разработчикrsjoomla

Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative acces…

11.06.2025
Критическая CVSS 9.8

CVE-2025-22204

РасширениеRegularlabs Sourcerer
Разработчикregularlabs

Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

04.02.2025
Критическая CVSS 9.3

CVE-2024-11145

Разработчикgithub

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! applicati…

26.11.2024