База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2009-2014

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action…

09.06.2009
Средняя CVSS 4.3

CVE-2009-1940

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script o…

05.06.2009
Средняя CVSS 4.3

CVE-2009-1939

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

05.06.2009
Средняя CVSS 4.3

CVE-2009-1938

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output an…

05.06.2009
Высокая CVSS 7.5

CVE-2009-1848

РасширениеJoomlame Com Agoragroup
Разработчикsecurityfocus

SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id paramet…

01.06.2009
Высокая CVSS 7.5

CVE-2009-1822

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

Multiple PHP remote file inclusion vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in t…

29.05.2009
Высокая CVSS 7.5

CVE-2009-1736

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid paramete…

20.05.2009
Высокая CVSS 7.5

CVE-2009-1499

РасширениеJoomla Joomla\!
Разработчикsecurityfocus

SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: Secur…

01.05.2009
Средняя CVSS 5.0

CVE-2009-1496

РасширениеJoomla Joomla
Разработчикsecurityfocus

Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewi…

01.05.2009
Средняя CVSS 6.8

CVE-2009-1280

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified vict…

09.04.2009
Низкая CVSS 2.6

CVE-2009-1279

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin c…

09.04.2009
Высокая CVSS 7.5

CVE-2009-1263

РасширениеJoomla Joomla
Разработчикosvdb

SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid par…

07.04.2009
Высокая CVSS 7.5

CVE-2009-1258

РасширениеRd-media Com Rdautos
Разработчикosvdb

SQL injection vulnerability in the RD-Autos (com_rdautos) component 1.5.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the makeid parameter in index.php. NOTE:…

07.04.2009
Высокая CVSS 7.5

CVE-2008-6653

РасширениеJoomla Joomla
Разработчикforum.wh-com.de

SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL comma…

07.04.2009
Высокая CVSS 7.5

CVE-2008-6489

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.

19.03.2009
Высокая CVSS 7.5

CVE-2008-6483

Разработчикosvdb

PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attacker…

18.03.2009
Средняя CVSS 6.8

CVE-2008-6482

РасширениеJustjoomla Com Treeg
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to exec…

18.03.2009
Высокая CVSS 7.5

CVE-2008-6481

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit…

17.03.2009