База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2009-3644

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.

09.10.2009
Высокая CVSS 7.5

CVE-2009-3491

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0]…

30.09.2009
Высокая CVSS 7.5

CVE-2009-3481

РасширениеIsygen Com Icrmbasic
Разработчикsecunia

A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors.…

30.09.2009
Высокая CVSS 7.5

CVE-2009-3480

РасширениеIsygen Icrm Basic
Разработчикosvdb

SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p3 parameter to index.php. NOT…

30.09.2009
Высокая CVSS 7.5

CVE-2009-3446

РасширениеRick Estrada Com Mytube
Разработчикexploit-db

SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in…

28.09.2009
Высокая CVSS 7.5

CVE-2009-3443

Разработчикpacketstormsecurity

SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to inde…

28.09.2009
Высокая CVSS 7.5

CVE-2009-3434

РасширениеOnestopjoomla Com Tupinambis
Разработчикpacketstormsecurity

SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a…

28.09.2009
Высокая CVSS 7.5

CVE-2009-3417

РасширениеIdojoomla Com Idoblog
Разработчикsecunia

SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile a…

25.09.2009
Средняя CVSS 4.3

CVE-2009-3368

РасширениеJoomlahbs Com Hbssearch
Разработчикe-rdc

Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or H…

24.09.2009
Высокая CVSS 7.5

CVE-2009-3357

РасширениеJoomla Joomla
Разработчикe-rdc

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via…

24.09.2009
Высокая CVSS 7.5

CVE-2009-3342

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary S…

24.09.2009
Высокая CVSS 7.5

CVE-2009-3335

РасширениеJoomla Joomla\!
Разработчикexploit-db

SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

24.09.2009
Высокая CVSS 7.5

CVE-2009-3334

РасширениеLhacky Com Jinc
Разработчикexploit-db

SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbit…

23.09.2009
Высокая CVSS 7.5

CVE-2009-3332

РасширениеSopinet Com Jbudgetsmagic
Разработчикexploit-db

SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid paramete…

23.09.2009
Высокая CVSS 7.5

CVE-2009-3325

РасширениеFocusdev Com Surveymanager
Разработчикexploit-db

SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the st…

23.09.2009
Высокая CVSS 7.5

CVE-2009-3318

РасширениеJoomla Joomla
Разработчикexploit-db

Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other imp…

23.09.2009
Высокая CVSS 7.5

CVE-2009-3316

РасширениеJoomla Joomla
Разработчикosvdb

SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pro…

23.09.2009