База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 200

Критическая CVSS 9.8

CVE-2023-23753

РасширениеVi-solutions Visforms
Разработчикblog.asturhackers.es

The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be…

23.04.2023
Критическая CVSS 9.8

CVE-2023-28731

РасширениеAcymailing Acymailing
Разработчикacymailing

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowin…

30.03.2023
Критическая CVSS 9.8

CVE-2022-23799

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

30.03.2022
Критическая CVSS 9.8

CVE-2022-23797

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.

30.03.2022
Критическая CVSS 9.8

CVE-2022-23795

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances a…

30.03.2022
Критическая CVSS 9.1

CVE-2021-26040

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.

24.08.2021
Критическая CVSS 9.8

CVE-2010-1435

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens f…

21.06.2021
Критическая CVSS 9.8

CVE-2010-1433

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulner…

21.06.2021
Критическая CVSS 9.1

CVE-2021-23128

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has…

04.03.2021
Критическая CVSS 9.1

CVE-2021-23127

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.

04.03.2021
Критическая CVSS 9.8

CVE-2020-35613

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.

28.12.2020
Критическая CVSS 9.8

CVE-2020-10243

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.

16.03.2020
Критическая CVSS 9.8

CVE-2011-4908

РасширениеTiny Tinybrowser
Разработчикvulmon

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

12.02.2020
Критическая CVSS 9.8

CVE-2011-4906

РасширениеTiny Tinybrowser
Разработчикdeveloper.joomla

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

12.02.2020
Критическая CVSS 9.8

CVE-2014-8739

Разработчикosvdb

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly S…

08.02.2020
Критическая CVSS 9.8

CVE-2019-17527

РасширениеJoomsky Js Jobs
Разработчикgist.github

dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldt…

19.12.2019
Критическая CVSS 9.8

CVE-2019-19846

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

18.12.2019