База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 4.3

CVE-2012-3828

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the Host HTTP Header.

03.07.2012
Средняя CVSS 5.0

CVE-2012-2748

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate filtering" and a "SQL error."

03.07.2012
Высокая CVSS 7.5

CVE-2012-2747

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."

03.07.2012
Средняя CVSS 6.0

CVE-2012-2902

Разработчикosvdb

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero,…

21.05.2012
Средняя CVSS 4.3

CVE-2012-2901

Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HT…

21.05.2012
Средняя CVSS 4.3

CVE-2012-1018

Разработчикdl.packetstormsecurity

Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitr…

08.02.2012
Средняя CVSS 6.0

CVE-2011-5004

РасширениеFabrikar Com Fabrikar
Разработчикsecunia

Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to exe…

25.12.2011
Низкая CVSS 3.5

CVE-2011-4830

РасширениеBarter-sites Com Listing
Разработчикdocs.joomla

Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or…

15.12.2011
Высокая CVSS 7.5

CVE-2011-4829

РасширениеBarter-sites Com Listing
Разработчикdocs.joomla

SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter to…

15.12.2011
Высокая CVSS 7.5

CVE-2011-4823

Разработчикdocs.joomla

Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract paramet…

15.12.2011
Средняя CVSS 4.3

CVE-2011-4809

Разработчикjoomlaextensions.co.in

Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via…

14.12.2011
Высокая CVSS 7.5

CVE-2011-4808

Разработчикjoomlaextensions.co.in

SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_h…

14.12.2011
Средняя CVSS 5.0

CVE-2011-4804

РасширениеFoobla Com Obsuggest
Разработчикfoobla

Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller para…

14.12.2011
Высокая CVSS 7.5

CVE-2011-4571

РасширениеEaimproved Com Estateagent
Разработчикpacketstormsecurity

SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to…

29.11.2011
Высокая CVSS 7.5

CVE-2011-4570

РасширениеTakeaweb Com Timereturns
Разработчикosvdb

SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the i…

29.11.2011
Средняя CVSS 4.3

CVE-2011-4332

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

23.11.2011
Средняя CVSS 5.0

CVE-2011-4321

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecif…

23.11.2011
Высокая CVSS 7.5

CVE-2010-5056

РасширениеGbu Grafici Com Gbufacebook
Разработчикpacketstormsecurity

SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_f…

23.11.2011