База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Средняя CVSS 6.5

CVE-2014-9102

РасширениеKunena Kunena
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array pa…

26.11.2014
Высокая CVSS 7.5

CVE-2014-7228

РасширениеJoomla Joomla\!
Разработчикjoomla

Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Profess…

03.11.2014
Средняя CVSS 4.3

CVE-2014-3863

Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a f…

20.10.2014
Средняя CVSS 4.3

CVE-2012-2413

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie paramete…

20.10.2014
Высокая CVSS 7.5

CVE-2014-7984

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving GMail authentication.

08.10.2014
Средняя CVSS 4.3

CVE-2014-7983

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vector…

08.10.2014
Средняя CVSS 4.3

CVE-2014-7982

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

08.10.2014
Высокая CVSS 7.5

CVE-2014-7981

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

08.10.2014
Средняя CVSS 5.0

CVE-2014-7229

РасширениеJoomla Joomla\!
Разработчикjoomla

Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of service via unspecified vectors.

08.10.2014
Высокая CVSS 7.5

CVE-2014-6632

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authenticati…

08.10.2014
Средняя CVSS 4.3

CVE-2014-6631

РасширениеJoomla Joomla\!
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x before 3.2.5 and 3.3.x before 3.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vec…

08.10.2014
Высокая CVSS 7.5

CVE-2014-4960

РасширениеJoomlaboat Com Youtubegallery
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to exe…

21.07.2014
Средняя CVSS 4.3

CVE-2013-5956

РасширениеJoomlaboat Com Youtubegallery
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) component 3.4.0 for Joomla! allows remote attackers to inject arbitrary web…

25.04.2014
Низкая CVSS 2.6

CVE-2013-5951

РасширениеExtplorer Extplorer
Разработчикarchives.neohapsis

Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO…

25.03.2014
Средняя CVSS 4.3

CVE-2013-5955

РасширениеPurplebeanie Com Pbbooking
Разработчикpurplebeanie

Cross-site scripting (XSS) vulnerability in manage.php in the PBBooking (com_pbbooking) component 2.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the an a…

19.03.2014
Средняя CVSS 4.3

CVE-2013-5953

РасширениеCodepeople Com Multicalendar
Разработчикcodepeople

Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow…

19.03.2014
Средняя CVSS 4.3

CVE-2013-5952

РасширениеCodologic Com Freichat
Разработчикjoomla

Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or…

19.03.2014
Средняя CVSS 4.3

CVE-2013-1636

РасширениеCaseproof Prettylinks
Разработчикarchives.neohapsis

Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jn…

12.03.2014