База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 107

Высокая CVSS 8.2

CVE-2026-48898

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-40383

Разработчикjoomla

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

26.05.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-35223

Разработчикjoomla

An improper access check allows unauthorized access to com_config webservice endpoints.

26.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25381

Разработчикextro.media

Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers…

25.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25380

Разработчикextro.media

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, an…

25.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25351

Разработчикexploit-db

Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into t…

23.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25348

Разработчикexploit-db

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter…

23.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25330

Разработчикexploit-db

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST para…

17.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2020-37226

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2020-37224

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 8.7

CVE-2020-37219

Разработчикfabrikar

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send…

13.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2020-37218

Разработчикexploit-db

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code th…

13.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2021-47930

Разработчикbalbooa

Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Atta…

10.05.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-34424

Разработчикpatchstack

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers…

09.04.2026 Требует внимания
Критическая CVSS 9.5

CVE-2026-21627

Разработчикtassos.gr

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functional…

20.02.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21624

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21623

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания