База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2010-4862

Разработчикosvdb

SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in…

05.10.2011
Высокая CVSS 7.5

CVE-2010-4853

РасширениеChillcreations Com Ccinvoices
Разработчикpacketstormsecurity

SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to in…

05.10.2011
Высокая CVSS 7.5

CVE-2008-7302

Разработчикnbill.co.uk

SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors…

05.10.2011
Средняя CVSS 5.0

CVE-2011-3747

РасширениеJoomla Joomla\!
Разработчикcode.google

Joomla! 1.6.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by librar…

23.09.2011
Средняя CVSS 6.0

CVE-2010-4838

РасширениеExtensiondepot Com Jsupport
Разработчикpacketstormsecurity

SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands…

14.09.2011
Средняя CVSS 4.3

CVE-2010-4837

РасширениеExtensiondepot Com Jsupport
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter…

14.09.2011
Средняя CVSS 4.3

CVE-2011-2892

РасширениеJoomla Joomla\!
Разработчикbl0g.yehg

Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a cr…

27.07.2011
Средняя CVSS 5.0

CVE-2011-2891

РасширениеJoomla Joomla\!
Разработчикbl0g.yehg

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message,…

27.07.2011
Средняя CVSS 5.0

CVE-2011-2890

РасширениеJoomla Joomla\!
Разработчикopenwall

The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors in…

27.07.2011
Средняя CVSS 5.0

CVE-2011-2889

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

templates/system/error.php in Joomla! before 1.5.23 might allow remote attackers to obtain sensitive information via unspecified vectors that trigger an undefined value of a certain error f…

27.07.2011
Средняя CVSS 4.3

CVE-2011-2710

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reacha…

27.07.2011
Средняя CVSS 4.3

CVE-2011-2509

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact compone…

27.07.2011
Средняя CVSS 5.0

CVE-2011-2488

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.

27.07.2011
Высокая CVSS 7.5

CVE-2010-4795

РасширениеJoomlaseller Com Jscalendar
Разработчикadv.salvatorefresta

SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a…

27.04.2011
Средняя CVSS 4.3

CVE-2010-4794

РасширениеJoomlaseller Com Jscalendar
Разработчикadv.salvatorefresta

Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web scr…

27.04.2011
Высокая CVSS 7.5

CVE-2010-4769

РасширениеJanguo Com Jimtawl
Разработчикsecunia

Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (d…

23.03.2011
Высокая CVSS 7.5

CVE-2010-4739

РасширениеAretimes Com Maianmedia
Разработчикpacketstormsecurity

SQL injection vulnerability in the Maian Media Silver (com_maianmedia) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a music actio…

16.02.2011
Высокая CVSS 7.5

CVE-2010-4720

РасширениеHarmistechnology Com Jeauto
Разработчикosvdb

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component before 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors relate…

01.02.2011