База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2009-3215

РасширениеPhp-shop-system Ixxo Cart
Разработчикsecunia

SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent p…

16.09.2009
Высокая CVSS 7.5

CVE-2009-3193

РасширениеJoomla Joomla
Разработчикexploit-db

SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to…

15.09.2009
Средняя CVSS 4.3

CVE-2009-3155

РасширениеJoomla Joomla
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the…

10.09.2009
Высокая CVSS 7.5

CVE-2009-3154

РасширениеJoomla Joomla
Разработчикsecunia

SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_re…

10.09.2009
Высокая CVSS 7.5

CVE-2008-7169

РасширениеJabode Com Jabode
Разработчикsecurityfocus

SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.

08.09.2009
Высокая CVSS 7.5

CVE-2009-3063

РасширениеJoomla Joomla
Разработчикexploit-db

SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel actio…

03.09.2009
Высокая CVSS 7.5

CVE-2009-3054

РасширениеJoomla Joomla
Разработчикexploit-db

SQL injection vulnerability in the Artetics.com Art Portal (com_artportal) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to…

03.09.2009
Средняя CVSS 6.8

CVE-2009-3053

РасширениеJoomla Joomla
Разработчикexploit-db

Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequence…

03.09.2009
Высокая CVSS 7.5

CVE-2008-7033

РасширениеGalore Com Simpleshop
Разработчикosvdb

SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section…

24.08.2009
Высокая CVSS 7.5

CVE-2009-2789

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php…

17.08.2009
Высокая CVSS 7.5

CVE-2009-2782

РасширениеJoomla Joomla
Разработчикexploit-db

SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

17.08.2009
Высокая CVSS 7.5

CVE-2008-6923

РасширениеJoomla Joomla
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory act…

10.08.2009
Высокая CVSS 7.5

CVE-2008-6883

РасширениеJoomla Joomla
Разработчикsecunia

SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NO…

30.07.2009
Высокая CVSS 7.5

CVE-2008-6882

РасширениеJoomla Joomla
Разработчикsecurityfocus

Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks…

30.07.2009
Высокая CVSS 7.5

CVE-2008-6881

РасширениеJoompolitan Com Livechat
Разработчикsecunia

Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getCh…

30.07.2009
Высокая CVSS 7.5

CVE-2009-2638

РасширениеJoomla Joomla
Разработчикexploit-db

SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to inde…

28.07.2009
Высокая CVSS 7.5

CVE-2009-2637

РасширениеJoomla Joomla
Разработчикexploit-db

PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via…

28.07.2009
Высокая CVSS 7.5

CVE-2009-2635

РасширениеJoomla Joomla
Разработчикexploit-db

PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP…

28.07.2009