База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 7.5

CVE-2010-2907

РасширениеHuruhelpdesk Com Huruhelpdesk
Разработчикpacketstormsecurity

SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail acti…

28.07.2010
Средняя CVSS 6.8

CVE-2010-2857

РасширениеDanieljamesscott Com Music
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in…

25.07.2010
Высокая CVSS 7.5

CVE-2010-2851

РасширениеOrdasoft Com Booklibrary
Разработчикsecunia

SQL injection vulnerability in the BookLibrary From Same Author (com_booklibrary) module 1.5 and possibly earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via t…

25.07.2010
Средняя CVSS 5.0

CVE-2010-2848

РасширениеGonzalo Maser Com Artforms
Разработчикpacketstormsecurity

Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to read…

25.07.2010
Высокая CVSS 7.5

CVE-2010-2847

РасширениеGonzalo Maser Com Artforms
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allow remote attackers to execute arbitrary SQL commands via the viewform…

25.07.2010
Средняя CVSS 4.3

CVE-2010-2846

РасширениеGonzalo Maser Com Artforms
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the…

25.07.2010
Высокая CVSS 7.5

CVE-2010-2845

РасширениеSchlu.net Com Quickfaq
Разработчикpacketstormsecurity

SQL injection vulnerability in the QuickFAQ (com_quickfaq) component 1.0.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a category actio…

25.07.2010
Средняя CVSS 6.8

CVE-2009-4946

РасширениеThetricky Com Messaging
Разработчикosvdb

Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote attackers to include and execute arbitrary local files via directory trav…

22.07.2010
Высокая CVSS 7.5

CVE-2009-4938

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the JVideo! (com_jvideo) component 0.3.11c Beta and 0.3.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a…

22.07.2010
Высокая CVSS 7.5

CVE-2010-2694

РасширениеRedcomponent Com Redshop
Разработчикsecunia

SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter to index.php.

12.07.2010
Высокая CVSS 7.5

CVE-2010-2690

РасширениеJooforge Com Gamesbox
Разработчикexploit-db

SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id p…

12.07.2010
Высокая CVSS 7.5

CVE-2010-2682

РасширениеRealtyna Com Realtyna
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other…

12.07.2010
Высокая CVSS 7.5

CVE-2010-2681

РасширениеJoomla Com Sef
Разработчикjoomla

PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path paramet…

12.07.2010
Средняя CVSS 6.8

CVE-2010-2680

Разработчикjoomla

Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files…

12.07.2010
Высокая CVSS 7.5

CVE-2010-2679

РасширениеJoomla Com Weblinks
Разработчикjoomla

SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

08.07.2010
Высокая CVSS 7.5

CVE-2010-2678

РасширениеGuillermo Vargas Com Xmap
Разработчикjoomla

SQL injection vulnerability in xmap (com_xmap) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

08.07.2010
Высокая CVSS 7.5

CVE-2010-2622

РасширениеJoomanager Joomanager
Разработчикjoomla

SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

02.07.2010
Средняя CVSS 4.3

CVE-2010-2613

РасширениеHarmistechnology Com Awd Song
Разработчикjoomla

Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song revi…

02.07.2010