Каталог CVE

Разработчик: developer.joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 159

Разработчик: developer.joomla
Средняя CVSS 6.1

CVE-2020-13761

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.

02.06.2020
Средняя CVSS 5.3

CVE-2020-11891

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.

21.04.2020
Средняя CVSS 5.3

CVE-2020-11890

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.

21.04.2020
Средняя CVSS 5.3

CVE-2020-11889

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.

21.04.2020
Критическая CVSS 9.8

CVE-2020-10243

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.

16.03.2020
Средняя CVSS 6.1

CVE-2020-10242

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.

16.03.2020
Высокая CVSS 8.8

CVE-2020-10241

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

16.03.2020
Средняя CVSS 5.3

CVE-2020-10240

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.

16.03.2020
Высокая CVSS 8.8

CVE-2020-10239

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

16.03.2020
Высокая CVSS 7.5

CVE-2020-10238

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

16.03.2020
Критическая CVSS 9.8

CVE-2011-4906

РасширениеTiny Tinybrowser
Разработчикdeveloper.joomla

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

12.02.2020
Средняя CVSS 6.1

CVE-2020-8421

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.

28.01.2020
Высокая CVSS 8.8

CVE-2020-8420

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

28.01.2020
Высокая CVSS 8.8

CVE-2020-8419

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

28.01.2020
Критическая CVSS 9.8

CVE-2019-19846

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

18.12.2019