База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Средняя CVSS 5.0

CVE-2010-2848

РасширениеGonzalo Maser Com Artforms
Разработчикpacketstormsecurity

Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to read…

25.07.2010
Высокая CVSS 7.5

CVE-2010-2847

РасширениеGonzalo Maser Com Artforms
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allow remote attackers to execute arbitrary SQL commands via the viewform…

25.07.2010
Средняя CVSS 4.3

CVE-2010-2846

РасширениеGonzalo Maser Com Artforms
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the…

25.07.2010
Высокая CVSS 7.5

CVE-2010-2845

РасширениеSchlu.net Com Quickfaq
Разработчикpacketstormsecurity

SQL injection vulnerability in the QuickFAQ (com_quickfaq) component 1.0.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a category actio…

25.07.2010
Средняя CVSS 6.8

CVE-2009-4946

РасширениеThetricky Com Messaging
Разработчикosvdb

Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote attackers to include and execute arbitrary local files via directory trav…

22.07.2010
Высокая CVSS 7.5

CVE-2009-4938

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the JVideo! (com_jvideo) component 0.3.11c Beta and 0.3.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a…

22.07.2010
Высокая CVSS 7.5

CVE-2010-2694

РасширениеRedcomponent Com Redshop
Разработчикsecunia

SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter to index.php.

12.07.2010
Высокая CVSS 7.5

CVE-2010-2690

РасширениеJooforge Com Gamesbox
Разработчикexploit-db

SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id p…

12.07.2010
Высокая CVSS 7.5

CVE-2010-2682

РасширениеRealtyna Com Realtyna
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other…

12.07.2010
Высокая CVSS 7.5

CVE-2010-2681

РасширениеJoomla Com Sef
Разработчикjoomla

PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path paramet…

12.07.2010
Средняя CVSS 6.8

CVE-2010-2680

Разработчикjoomla

Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files…

12.07.2010
Высокая CVSS 7.5

CVE-2010-2679

РасширениеJoomla Com Weblinks
Разработчикjoomla

SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

08.07.2010
Высокая CVSS 7.5

CVE-2010-2678

РасширениеGuillermo Vargas Com Xmap
Разработчикjoomla

SQL injection vulnerability in xmap (com_xmap) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

08.07.2010
Высокая CVSS 7.5

CVE-2010-2622

РасширениеJoomanager Joomanager
Разработчикjoomla

SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

02.07.2010
Средняя CVSS 4.3

CVE-2010-2613

РасширениеHarmistechnology Com Awd Song
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song revi…

02.07.2010
Высокая CVSS 7.5

CVE-2010-1522

РасширениеOrdasoft Com Booklibrary
Разработчикjoomla

Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL command…

02.07.2010
Средняя CVSS 6.8

CVE-2010-2515

РасширениеDacian Strain Com Jfaq
Разработчикjoomla

Multiple SQL injection vulnerabilities in index.php in the JFaq (com_jfaq) component 1.2 for Joomla!, when magic_quotes_gpc is disabled, allow (1) remote attackers to execute arbitrary SQL…

28.06.2010
Средняя CVSS 4.3

CVE-2010-2514

РасширениеDacian Strain Com Jfaq
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the question parameter in an add…

28.06.2010