База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2010-4719

РасширениеFxwebdesign Com Jradio
Разработчикpacketstormsecurity

Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controll…

01.02.2011
Средняя CVSS 4.3

CVE-2010-4718

РасширениеLyften Com Lyftenbloggie
Разработчикpacketstormsecurity

Multiple cross-site scripting (XSS) vulnerabilities in the Lyftenbloggie (com_lyftenbloggie) component 1.1.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via th…

01.02.2011
Высокая CVSS 7.5

CVE-2011-0511

РасширениеJoomtraders Com Allcinevid
Разработчикadv.salvatorefresta

SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

20.01.2011
Высокая CVSS 7.5

CVE-2010-4702

РасширениеFxwebdesign Com Jradio
Разработчикsecunia

SQL injection vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

20.01.2011
Высокая CVSS 7.5

CVE-2010-4696

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via the (1) filter_order or (2) filter_order_Dir parameter in…

18.01.2011
Высокая CVSS 7.5

CVE-2010-4166

РасширениеJoomla Joomla\!
Разработчикarchives.neohapsis

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_order parameter in a com_weblinks category…

18.01.2011
Средняя CVSS 4.3

CVE-2011-0005

РасширениеJoomla Com Search
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter…

11.01.2011
Средняя CVSS 6.8

CVE-2010-4638

РасширениеIptechinside Com Jquarks4s
Разработчикadv.salvatorefresta

SQL injection vulnerability in the submitSurvey function in controller.php in JQuarks4s (com_jquarks4s) component 1.0.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attacke…

30.12.2010
Средняя CVSS 4.3

CVE-2010-4618

РасширениеAlgisinfo Aicontactsafe
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the Algis Info aiContactSafe component before 2.0.14 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified v…

29.12.2010
Средняя CVSS 6.8

CVE-2010-4617

РасширениеKanich Com Jotloader
Разработчикpacketstormsecurity

Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the secti…

29.12.2010
Средняя CVSS 6.8

CVE-2010-4517

РасширениеHarmistechnology Com Jeauto
Разработчикexploit-db

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands v…

09.12.2010
Средняя CVSS 4.3

CVE-2010-4516

РасширениеJxtended Jxtended Comments
Разработчикjxtended

Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified…

09.12.2010
Средняя CVSS 4.3

CVE-2010-4405

РасширениеAnything-digital Sh404sef
Разработчикdev.anything-digital

Cross-site scripting (XSS) vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecifi…

06.12.2010
Высокая CVSS 7.5

CVE-2010-4404

РасширениеAnything-digital Sh404sef
Разработчикdev.anything-digital

SQL injection vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

06.12.2010
Высокая CVSS 7.5

CVE-2010-4272

РасширениеPulseinfotech Com Sponsorwall
Разработчикpacketstormsecurity

SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter…

17.11.2010
Средняя CVSS 5.0

CVE-2010-4270

Разработчикosvdb

Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrar…

17.11.2010
Высокая CVSS 7.5

CVE-2010-4268

РасширениеPulseinfotech Com Flipwall
Разработчикpacketstormsecurity

SQL injection vulnerability in the Pulse Infotech Flip Wall (com_flipwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to ind…

17.11.2010