База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2010-4968

РасширениеWebmaster-tips Com Wmtpic
Разработчикpacketstormsecurity

SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter…

01.11.2011
Средняя CVSS 4.3

CVE-2010-4949

РасширениеEvnix Freichat
Разработчикforum.joomla

Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4945

РасширениеJoomla Com Camelcitydb2
Разработчикpacketstormsecurity

SQL injection vulnerability in the CamelcityDB (com_camelcitydb2) component 2.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

09.10.2011
Высокая CVSS 7.5

CVE-2010-4944

РасширениеJoomla Com Elite Experts
Разработчикexploit-db

SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4941

РасширениеJoomlamo Com Teams
Разработчикadv.salvatorefresta

SQL injection vulnerability in the Teams (com_teams) component 1_1028_100809_1711 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PlayerID parameter in a playe…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4938

РасширениеJoomla Com Weblinks
Разработчикsecurityfocus

SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4937

РасширениеRobitbt Com Amblog
Разработчикadv.salvatorefresta

Multiple SQL injection vulnerabilities in the Amblog (com_amblog) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) articleid or (2) catid param…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4936

РасширениеWebmaster-tips Com Slideshow
Разработчикpacketstormsecurity

SQL injection vulnerability in the Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

09.10.2011
Высокая CVSS 7.5

CVE-2010-4929

РасширениеJoostina-cms Com Ezautos
Разработчикexploit-db

SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the firstCode parameter in a helpers action to…

09.10.2011
Средняя CVSS 4.3

CVE-2010-4928

Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML by placing…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4927

Разработчикpacketstormsecurity

SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a cou…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4926

РасширениеTimetrack Com Timetrack
Разработчикpacketstormsecurity

SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack act…

09.10.2011
Высокая CVSS 7.5

CVE-2010-4918

РасширениеIjoomla Com Magazine
Разработчикpacketstormsecurity

PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config paramete…

08.10.2011
Высокая CVSS 7.5

CVE-2010-4904

РасширениеSimon Philips Com Aardvertiser
Разработчикsecunia

SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter i…

08.10.2011
Высокая CVSS 7.5

CVE-2010-4902

РасширениеJoomla-clantools Clantools
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgam…

08.10.2011
Высокая CVSS 7.5

CVE-2010-4898

РасширениеGantry-framework Com Gantry
Разработчикosvdb

SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter to index.php.

08.10.2011
Высокая CVSS 7.5

CVE-2010-4865

Разработчикadv.salvatorefresta

SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_d…

05.10.2011
Высокая CVSS 7.5

CVE-2010-4864

Разработчикpacketstormsecurity

SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip present…

05.10.2011