База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2008-5051

РасширениеJooblog Jooblog
Разработчикsecurityreason

SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PostID parameter to index.php.

13.11.2008
Высокая CVSS 7.5

CVE-2008-4777

РасширениеJoomla Com Lms
Разработчикarchives.neohapsis

SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a show…

29.10.2008
Средняя CVSS 5.0

CVE-2008-4764

РасширениеExtplorer Com Extplorer
Разработчикsecurityfocus

Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir para…

28.10.2008
Высокая CVSS 7.5

CVE-2008-4715

РасширениеJpad Project Jpad
Разработчикsecurityreason

SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

23.10.2008
Высокая CVSS 9.0

CVE-2008-4668

РасширениеJoomla Com Imagebrowser
Разработчикsecurityreason

Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot)…

22.10.2008
Высокая CVSS 7.5

CVE-2008-4623

Разработчикsecunia

SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.p…

21.10.2008
Высокая CVSS 7.5

CVE-2008-4617

РасширениеPyxicom Actualite
Разработчикsecurityreason

SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

20.10.2008
Средняя CVSS 5.1

CVE-2008-4107

РасширениеPhp Php
Разработчикmarc.info

The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these funct…

18.09.2008
Высокая CVSS 7.5

CVE-2008-4105

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecif…

18.09.2008
Средняя CVSS 5.8

CVE-2008-4104

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.

18.09.2008
Средняя CVSS 5.0

CVE-2008-4103

РасширениеJoomla Com Mailto
Разработчикdeveloper.joomla

The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.

18.09.2008
Высокая CVSS 7.5

CVE-2008-4102

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated b…

18.09.2008
Высокая CVSS 7.5

CVE-2008-3681

РасширениеJoomla Com User
Разработчикdeveloper.joomla

components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" passwo…

14.08.2008
Высокая CVSS 7.5

CVE-2008-3586

РасширениеJoomla Com Ezstore
Разработчикsecurityfocus

SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.ph…

11.08.2008
Высокая CVSS 7.5

CVE-2008-3498

Разработчикsecunia

SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action…

06.08.2008
Средняя CVSS 6.8

CVE-2008-3265

РасширениеJoomla Com Dtregister
Разработчикosvdb

SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_opti…

24.07.2008
Высокая CVSS 10.0

CVE-2008-3225

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."

18.07.2008
Средняя CVSS 5.0

CVE-2008-3226

РасширениеJoomla Joomla
Разработчикjoomla

The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

18.07.2008