База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Средняя CVSS 6.8

CVE-2008-3265

РасширениеJoomla Com Dtregister
Разработчикosvdb

SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_opti…

24.07.2008
Высокая CVSS 10.0

CVE-2008-3225

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."

18.07.2008
Средняя CVSS 5.0

CVE-2008-3226

РасширениеJoomla Joomla
Разработчикjoomla

The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3227

РасширениеJoomla Joomla
Разработчикjoomla

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3228

РасширениеJoomla Joomla
Разработчикjoomla

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

18.07.2008
Высокая CVSS 7.5

CVE-2008-3132

РасширениеJoomla Com Beamospetition
Разработчикsecurityfocus

SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.

10.07.2008
Высокая CVSS 7.5

CVE-2008-3083

Разработчикsecunia

SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

09.07.2008
Высокая CVSS 7.5

CVE-2008-2990

РасширениеJoomla Com Facileforms
Разработчикsecurityreason

PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP…

02.07.2008
Высокая CVSS 7.5

CVE-2008-2892

РасширениеFeellove Exp Shop Component
Разработчикsecunia

SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment actio…

27.06.2008
Высокая CVSS 7.5

CVE-2008-2692

РасширениеJoomla Com Yvcomment
Разработчикsecunia

SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter i…

13.06.2008
Высокая CVSS 7.5

CVE-2008-2697

РасширениеJoomla Com Rapidrecipe
Разработчикsecunia

SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter…

13.06.2008
Средняя CVSS 6.8

CVE-2008-2701

РасширениеJoomla Com Gameq
Разработчикpacketstormsecurity

SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page…

13.06.2008
Высокая CVSS 7.5

CVE-2008-2676

РасширениеJoomla Com News Portal
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid param…

12.06.2008
Высокая CVSS 7.5

CVE-2008-2643

РасширениеJoomla Com Biblestudy
Разработчикjoomlacode

SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a media…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2651

РасширениеJoomla Com Joobb
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum param…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2627

РасширениеJoomla Com Idoblog
Разработчикsecunia

SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the userid…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2628

РасширениеJoomla Joomla
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

10.06.2008
Высокая CVSS 7.5

CVE-2008-2630

РасширениеJoomla Com Jb2
Разработчикsecunia

SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action…

10.06.2008