База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 4.3

CVE-2010-3712

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple…

28.10.2010
Низкая CVSS 3.5

CVE-2010-2535

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator…

05.10.2010
Высокая CVSS 7.5

CVE-2010-3426

Расширение4you-studio Com Jphone
Разработчикpacketstormsecurity

Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (d…

16.09.2010
Высокая CVSS 7.5

CVE-2010-3422

РасширениеSolventus Com Jgen
Разработчикexploit-db

SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

16.09.2010
Высокая CVSS 7.5

CVE-2010-3211

РасширениеJextn Com Jefaqpro
Разработчикsecunia

Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operat…

03.09.2010
Средняя CVSS 5.0

CVE-2010-3203

РасширениеXmlswf Com Picsell
Разработчикsecunia

Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prev…

03.09.2010
Низкая CVSS 3.6

CVE-2010-3028

РасширениеSimon Philips Aardvertiser
Разработчикsecunia

The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files.

16.08.2010
Высокая CVSS 7.5

CVE-2010-2923

РасширениеPrasanna Com Youtube
Разработчикpacketstormsecurity

SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.

30.07.2010
Высокая CVSS 7.5

CVE-2010-2921

Разработчикpacketstormsecurity

SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id…

30.07.2010
Средняя CVSS 6.8

CVE-2010-2920

РасширениеFoobla Com Foobla Suggestions
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal se…

30.07.2010
Высокая CVSS 7.5

CVE-2010-2919

РасширениеJoomlaxt Com Staticxt
Разработчикpacketstormsecurity

SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

30.07.2010
Высокая CVSS 7.5

CVE-2010-2918

РасширениеVisocrea Com Joomla Visites
Разработчикpacketstormsecurity

PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP…

30.07.2010
Высокая CVSS 7.5

CVE-2010-2910

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

28.07.2010
Высокая CVSS 7.5

CVE-2010-2909

РасширениеToughtomato Com Ttvideo
Разработчикadv.salvatorefresta

SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video…

28.07.2010
Высокая CVSS 7.5

CVE-2010-2908

РасширениеJoomdle Com Joomdle
Разработчикpacketstormsecurity

SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a de…

28.07.2010
Высокая CVSS 7.5

CVE-2010-2907

РасширениеHuruhelpdesk Com Huruhelpdesk
Разработчикpacketstormsecurity

SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail acti…

28.07.2010
Средняя CVSS 6.8

CVE-2010-2857

РасширениеDanieljamesscott Com Music
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in…

25.07.2010
Высокая CVSS 7.5

CVE-2010-2851

РасширениеOrdasoft Com Booklibrary
Разработчикsecunia

SQL injection vulnerability in the BookLibrary From Same Author (com_booklibrary) module 1.5 and possibly earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via t…

25.07.2010