База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2008-0517

РасширениеDarko Selesi Estateagent
Разработчикsecurityfocus

SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL command…

31.01.2008
Высокая CVSS 7.5

CVE-2008-0518

РасширениеJoomla Com Recipes
Разработчикsecurityfocus

SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in…

31.01.2008
Высокая CVSS 7.5

CVE-2008-0519

РасширениеJoomla Com Jokes
Разработчикsecurityfocus

SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter…

31.01.2008
Высокая CVSS 7.5

CVE-2007-6663

РасширениеPragmatic Utopia Pu Arcade
Разработчикosvdb

SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attac…

04.01.2008
Средняя CVSS 6.8

CVE-2007-6642

РасширениеJoomla Joomla
Разработчикosvdb

Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an extension containing arbitrary PHP code,…

04.01.2008
Средняя CVSS 4.3

CVE-2007-6643

РасширениеJoomla Joomla
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in the com_poll component in Joomla! before 1.5 RC4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

04.01.2008
Средняя CVSS 6.5

CVE-2007-6644

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security model.

04.01.2008
Высокая CVSS 7.5

CVE-2007-6645

РасширениеJoomla Joomla
Разработчикosvdb

Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered user privilege escalation vulnerability."

04.01.2008
Средняя CVSS 6.8

CVE-2007-6553

РасширениеGeorge Lewe Teamcal Pro
Разработчикosvdb

Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONF[app_root] parameter to (1) t…

28.12.2007
Высокая CVSS 9.3

CVE-2007-6555

РасширениеPhil Taylor Mosdirectory
Разработчикosvdb

PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code v…

28.12.2007
Высокая CVSS 7.5

CVE-2007-6362

РасширениеJoomla Rs Gallery2
Разработчикadvisories.echo.or.id

SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands vi…

15.12.2007
Высокая CVSS 7.5

CVE-2007-6272

РасширениеJoomla Joomla
Разработчикsecurityreason

Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2)…

07.12.2007
Средняя CVSS 6.8

CVE-2007-6038

РасширениеJoomlaequipment Juser
Разработчикsecurityfocus

PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the m…

20.11.2007
Средняя CVSS 6.8

CVE-2007-6027

Разработчикsecurityfocus

PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP cod…

20.11.2007
Средняя CVSS 4.3

CVE-2007-5577

РасширениеJoomla Joomla\!
Разработчикjoomlacode

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Nam…

18.10.2007
Средняя CVSS 6.8

CVE-2007-5457

РасширениеJoomla Joomla
Разработчикsecurityfocus

Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to exec…

14.10.2007
Средняя CVSS 6.8

CVE-2007-5451

РасширениеCom Colorlab Com Colorlab
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in t…

14.10.2007
Средняя CVSS 4.3

CVE-2007-5427

РасширениеJoomla Com Search Component
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword paramete…

12.10.2007