База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 7.5

CVE-2008-2632

РасширениеJoomla Com Acctexp
Разработчикexchange.xforce.ibmcloud

SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subs…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2633

РасширениеJoomla Com Joomradio
Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1)…

10.06.2008
Высокая CVSS 7.5

CVE-2008-2564

РасширениеJoomla Com Jotloader
Разработчикsecunia

SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to ind…

06.06.2008
Высокая CVSS 7.5

CVE-2008-2568

РасширениеJoomla Com Simpleshop
Разработчикsecunia

SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid paramete…

06.06.2008
Высокая CVSS 7.5

CVE-2008-2569

РасширениеJoomla Easybook Component
Разработчикsecunia

SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action…

06.06.2008
Высокая CVSS 7.5

CVE-2008-2454

РасширениеJoomla Com Xsstream-dm
Разработчикsecurityfocus

SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the movie parameter to index.p…

27.05.2008
Высокая CVSS 7.5

CVE-2008-2093

РасширениеJoomla Com Comprofiler
Разработчикsecurityfocus

SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user par…

06.05.2008
Высокая CVSS 7.5

CVE-2008-2095

РасширениеJoomla Com Flippingbook
Разработчикsecurityfocus

SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id paramet…

06.05.2008
Высокая CVSS 7.5

CVE-2008-1935

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.

25.04.2008
Высокая CVSS 7.5

CVE-2008-1890

РасширениеJoomla Joomla
Разработчикsecunia

SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of…

18.04.2008
Средняя CVSS 4.3

CVE-2008-1848

РасширениеJoomla Joomla
Разработчикsecurityfocus

Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML vi…

16.04.2008
Средняя CVSS 5.0

CVE-2008-1849

РасширениеJoomlacode Joomlaexplorer
Разработчикsecurityfocus

Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a…

16.04.2008
Высокая CVSS 7.5

CVE-2008-1733

РасширениеJoomla Joomla
Разработчикsecurityreason

SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL com…

11.04.2008
Средняя CVSS 6.8

CVE-2008-1682

Разработчикsecurityfocus

PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitra…

04.04.2008
Средняя CVSS 6.8

CVE-2008-1559

РасширениеBernard Gilly Com Alphacontent
Разработчикsecurityfocus

SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter i…

31.03.2008
Высокая CVSS 7.5

CVE-2008-1535

Разработчикsecunia

SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the op_id pa…

28.03.2008
Высокая CVSS 7.5

CVE-2008-1540

РасширениеJoomla Datsogallery
Разработчикsecurityfocus

SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a det…

28.03.2008
Средняя CVSS 6.8

CVE-2008-1533

РасширениеJoomla Joomla
Разработчикsecunia

Unspecified vulnerability in the XML-RPC Blogger API plugin in Joomla! 1.5 allows remote attackers to perform unauthorized article operations on articles via unknown vectors.

28.03.2008