База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2010-0632

Разработчикpacketstormsecurity

SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in…

12.02.2010
Высокая CVSS 7.5

CVE-2010-0610

РасширениеWebguerilla Com Photoblog
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images ac…

11.02.2010
Средняя CVSS 5.8

CVE-2010-0467

Разработчикsecunia

Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller par…

02.02.2010
Средняя CVSS 6.5

CVE-2010-0461

РасширениеJoomla Com Casino
Разработчикpacketstormsecurity

SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) play…

28.01.2010
Высокая CVSS 7.5

CVE-2010-0459

РасширениеYoflash Com Mochigames
Разработчикpacketstormsecurity

SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id pa…

28.01.2010
Высокая CVSS 7.5

CVE-2010-0456

РасширениеIndianpulses Com Gameserver
Разработчикexploit-db

SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a ga…

28.01.2010
Средняя CVSS 4.3

CVE-2010-0374

РасширениеCodingfish Com Marketplace
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid paramete…

21.01.2010
Высокая CVSS 7.5

CVE-2010-0373

РасширениеJoomla Com Libros
Разработчикpacketstormsecurity

SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

21.01.2010
Высокая CVSS 7.5

CVE-2010-0372

РасширениеHong Chuyen Com Articlemanager
Разработчикpacketstormsecurity

SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display a…

21.01.2010
Высокая CVSS 7.5

CVE-2009-4628

РасширениеTemplateplaza Com Tpdugg
Разработчикevilc0de.blogspot

SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags a…

18.01.2010
Высокая CVSS 7.5

CVE-2009-4625

Разработчикosvdb

SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6,…

18.01.2010
Высокая CVSS 7.5

CVE-2009-4620

РасширениеJoomloc Com Joomloc
Разработчикosvdb

SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

18.01.2010
Высокая CVSS 7.5

CVE-2009-4619

РасширениеLucygames Com Lucygames
Разработчикexploit-db

SQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action…

18.01.2010
Высокая CVSS 7.5

CVE-2009-4604

РасширениеFernando Soares Com Mamboleto
Разработчикpacketstormsecurity

PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code…

12.01.2010
Высокая CVSS 7.5

CVE-2009-4599

РасширениеJoomshark Com Jsjobs
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the md parameter in an empl…

12.01.2010
Высокая CVSS 7.5

CVE-2009-4598

РасширениеCorephp Com Jphoto
Разработчикosvdb

SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action to index…

12.01.2010
Высокая CVSS 7.5

CVE-2010-0158

РасширениеJoomlabamboo Jb Simpla
Разработчикpacketstormsecurity

SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to…

06.01.2010
Высокая CVSS 7.5

CVE-2010-0157

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in th…

06.01.2010