База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2008-5957

РасширениеMydyngallery Mydyngallery
Разработчикsecurityfocus

SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index…

23.01.2009
Средняя CVSS 5.0

CVE-2009-0113

РасширениеJoomla Xstandard
Разработчикsecunia

Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot)…

09.01.2009
Высокая CVSS 7.5

CVE-2008-5875

РасширениеJoomlahbs Com Lowcosthotels
Разработчикsecurityreason

SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via th…

08.01.2009
Высокая CVSS 7.5

CVE-2008-5874

РасширениеJoomlahbs Com 5starhotels
Разработчикdownloads.securityfocus

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showh…

08.01.2009
Высокая CVSS 7.5

CVE-2008-5865

Разработчикsecunia

SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands…

06.01.2009
Высокая CVSS 7.5

CVE-2008-5864

РасширениеJoomlahbs Com Tophotelmodule
Разработчикsecurityreason

SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitr…

06.01.2009
Высокая CVSS 7.5

CVE-2008-5811

РасширениеJoomla Com Paxgallery
Разработчикosvdb

SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to…

02.01.2009
Средняя CVSS 6.8

CVE-2008-5793

РасширениеRecly Clickheat-heatmap
Разработчикsecurityreason

Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a UR…

31.12.2008
Высокая CVSS 7.5

CVE-2008-5790

РасширениеRecly Competitions
Разработчикsecurityfocus

Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in t…

31.12.2008
Высокая CVSS 7.5

CVE-2008-5789

РасширениеRecly Interactive Feederator
Разработчикsecurityreason

Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via…

31.12.2008
Высокая CVSS 7.5

CVE-2008-4122

РасширениеJoomla Joomla\!
Разработчикint21.de

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission wit…

19.12.2008
Высокая CVSS 7.5

CVE-2008-5671

РасширениеJoomla Joomla
Разработчикsecunia

PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP co…

19.12.2008
Высокая CVSS 7.5

CVE-2008-5643

РасширениеJoomla Com Books
Разработчикsecurityreason

SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter in a book_details action to in…

17.12.2008
Высокая CVSS 7.5

CVE-2008-5607

РасширениеJoomitaly Jmovies
Разработчикsecurityreason

SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

16.12.2008
Высокая CVSS 7.5

CVE-2008-5494

РасширениеDigitalgreys Com Contactinfo
Разработчикsecurityreason

SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter t…

12.12.2008
Высокая CVSS 7.5

CVE-2008-5208

РасширениеJoomla Com Datsogallery
Разработчикsecunia

SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTT…

24.11.2008
Высокая CVSS 7.5

CVE-2008-5200

РасширениеJoomla Com Xewebtv
Разработчикsecurityreason

SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.ph…

21.11.2008
Высокая CVSS 10.0

CVE-2008-5053

РасширениеJoomla Com Rssreader
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a…

13.11.2008