База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2006-7123

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via…

06.03.2007
Высокая CVSS 7.5

CVE-2006-7124

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute…

06.03.2007
Средняя CVSS 6.8

CVE-2006-7125

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not pro…

06.03.2007
Средняя CVSS 6.8

CVE-2006-7126

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.

06.03.2007
Высокая CVSS 7.5

CVE-2006-7008

РасширениеJoomla Joomla
Разработчикsecunia

Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-10…

12.02.2007
Высокая CVSS 7.5

CVE-2006-7009

РасширениеJoomla Joomla
Разработчикsecunia

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

12.02.2007
Высокая CVSS 7.5

CVE-2006-7010

РасширениеJoomla Joomla
Разработчикsecunia

The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack…

12.02.2007
Средняя CVSS 6.8

CVE-2006-6962

РасширениеJoomla Rs Gallery2
Разработчикsecurityfocus

PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosCon…

29.01.2007
Средняя CVSS 6.8

CVE-2007-0373

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter…

19.01.2007
Высокая CVSS 7.5

CVE-2007-0374

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content e…

19.01.2007
Средняя CVSS 5.0

CVE-2007-0375

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/…

19.01.2007
Высокая CVSS 7.5

CVE-2007-0382

РасширениеLetterman Letterman
Разработчикarchives.neohapsis

Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL comm…

19.01.2007
Высокая CVSS 7.5

CVE-2007-0387

РасширениеJoomla Joomla
Разработчикarchives.neohapsis

SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid…

19.01.2007
Средняя CVSS 4.3

CVE-2006-6832

РасширениеJoomla Joomla
Разработчикforge.joomla

Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the…

31.12.2006
Высокая CVSS 7.5

CVE-2006-6833

РасширениеJoomla Joomla
Разработчикjvn.jp

com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

31.12.2006
Средняя CVSS 6.8

CVE-2006-6834

РасширениеJoomla Joomla
Разработчикjvn.jp

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

31.12.2006
Высокая CVSS 7.5

CVE-2006-6843

Разработчикsecurityfocus

PHP remote file inclusion vulnerability in the BE IT EasyPartner 0.0.9 beta component for Joomla! allows remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: The pr…

31.12.2006
Высокая CVSS 7.5

CVE-2006-6419

Разработчикsecunia

jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allows remote attackers to include and possibly execute arbitrar…

10.12.2006