База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2008-3227

РасширениеJoomla Joomla
Разработчикjoomla

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3228

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3132

РасширениеJoomla Com Beamospetition
Разработчикsecurityfocus

SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.

10.07.2008
Высокая CVSS 7.5

CVE-2008-3083

Разработчикsecunia

SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

09.07.2008
Высокая CVSS 7.5

CVE-2008-2990

РасширениеJoomla Com Facileforms
Разработчикsecurityreason

PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP…

02.07.2008
Высокая CVSS 7.5

CVE-2008-2892

РасширениеFeellove Exp Shop Component
Разработчикsecunia

SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment actio…

27.06.2008
Высокая CVSS 7.5

CVE-2008-2692

РасширениеJoomla Com Yvcomment
Разработчикsecunia

SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter i…

13.06.2008
Высокая CVSS 7.5

CVE-2008-2697

РасширениеJoomla Com Rapidrecipe
Разработчикsecunia

SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter…

13.06.2008
Средняя CVSS 6.8

CVE-2008-2701

РасширениеJoomla Com Gameq
Разработчикpacketstormsecurity

SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page…

13.06.2008
Высокая CVSS 7.5

CVE-2008-2676

РасширениеJoomla Com News Portal
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid param…

12.06.2008
Высокая CVSS 7.5

CVE-2008-2643

РасширениеJoomla Com Biblestudy
Разработчикjoomlacode

SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a media…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2651

РасширениеJoomla Com Joobb
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum param…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2627

РасширениеJoomla Com Idoblog
Разработчикsecunia

SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the userid…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2628

РасширениеJoomla Joomla
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

10.06.2008
Высокая CVSS 7.5

CVE-2008-2630

РасширениеJoomla Com Jb2
Разработчикsecunia

SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2632

РасширениеJoomla Com Acctexp
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subs…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2633

РасширениеJoomla Com Joomradio
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1)…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2564

РасширениеJoomla Com Jotloader
Разработчикsecunia

SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to ind…

06.06.2008