База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 7.5

CVE-2009-4598

РасширениеCorephp Com Jphoto
Разработчикosvdb

SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action to index…

12.01.2010
Высокая CVSS 7.5

CVE-2010-0158

РасширениеJoomlabamboo Jb Simpla
Разработчикpacketstormsecurity

SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to…

06.01.2010
Высокая CVSS 7.5

CVE-2010-0157

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in th…

06.01.2010
Высокая CVSS 7.5

CVE-2009-4583

РасширениеJoomla Com Dhforum
Разработчикpacketstormsecurity

SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.…

06.01.2010
Средняя CVSS 4.3

CVE-2009-4579

РасширениеJoomla Com Artistavenue
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the Artist avenue (com_artistavenue) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemi…

06.01.2010
Средняя CVSS 4.3

CVE-2009-4578

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid p…

06.01.2010
Высокая CVSS 7.5

CVE-2009-4576

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions…

06.01.2010
Средняя CVSS 4.3

CVE-2009-4575

РасширениеJoomla Joomla\!
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_si…

06.01.2010
Средняя CVSS 4.3

CVE-2009-4573

РасширениеJoomlabear Mod Joomulus
Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud para…

06.01.2010
Высокая CVSS 7.5

CVE-2009-4550

РасширениеJoomla Joomla\!
Разработчикsecunia

SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.…

04.01.2010
Высокая CVSS 7.5

CVE-2009-4475

РасширениеJoomlub Com Joomlub
Разработчикpacketstormsecurity

SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an auction edit action to i…

30.12.2009
Высокая CVSS 7.5

CVE-2009-4431

РасширениеJoomla Joomla\!
Разработчикpacketstormsecurity

PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for Joomla! allows remote attackers to execu…

28.12.2009
Высокая CVSS 7.5

CVE-2009-4428

РасширениеJoomplace Com Joomportfolio
Разработчикosvdb

SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showc…

28.12.2009
Средняя CVSS 4.3

CVE-2009-4255

РасширениеJoomla Joomla\!
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the You!Hostit! template 1.0.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the created_by_alias parameter in i…

10.12.2009
Средняя CVSS 4.3

CVE-2009-4233

РасширениеJoomla Joomla\!
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or HTML via…

08.12.2009
Средняя CVSS 5.0

CVE-2009-4232

РасширениеJonijnm Com Kide
Разработчикsecunia

The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an inser…

08.12.2009
Высокая CVSS 7.5

CVE-2009-4217

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an…

07.12.2009
Высокая CVSS 7.5

CVE-2009-4202

РасширениеJoomla Joomla\!
Разработчикexploit-db

Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via di…

04.12.2009