База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Средняя CVSS 4.3

CVE-2007-4779

РасширениеJoomla Joomla
Разработчикosvdb

Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to…

10.09.2007
Средняя CVSS 6.8

CVE-2007-4780

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scrip…

10.09.2007
Средняя CVSS 6.6

CVE-2007-4781

РасширениеJoomla Joomla
Разработчикosvdb

administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the…

10.09.2007
Высокая CVSS 7.5

CVE-2007-4502

РасширениеJoomla Bibtex
Разработчикosvdb

SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

23.08.2007
Высокая CVSS 7.5

CVE-2007-4503

РасширениеJoomla Nice Talk
Разработчикsecunia

SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid para…

23.08.2007
Средняя CVSS 5.0

CVE-2007-4504

РасширениеJoomla Rsfiles
Разработчикexchange.xforce.ibmcloud

Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the…

23.08.2007
Высокая CVSS 7.5

CVE-2007-4506

РасширениеJoomla Neorecruit
Разработчикosvdb

SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parame…

23.08.2007
Высокая CVSS 7.5

CVE-2007-4509

РасширениеJoomla Eventlist
Разработчикosvdb

SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did paramet…

23.08.2007
Высокая CVSS 7.5

CVE-2007-4456

РасширениеMambo Mambo
Разработчикsecunia

SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it…

21.08.2007
Высокая CVSS 7.5

CVE-2007-4244

РасширениеJoomla J Reactions
Разработчикsecurityreason

PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attackers to execute arbitrary PHP code via a U…

08.08.2007
Высокая CVSS 7.5

CVE-2007-4184

РасширениеJoomla Joomla
Разработчикsecurityfocus

SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.

08.08.2007
Средняя CVSS 5.0

CVE-2007-4185

РасширениеJoomla Joomla
Разработчикosvdb

Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and…

08.08.2007
Средняя CVSS 6.8

CVE-2007-4186

РасширениеJoomla Tour De France Pool
Разработчикosvdb

PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via…

08.08.2007
Высокая CVSS 7.5

CVE-2007-4187

РасширениеJoomla Joomla
Разработчикjoomlacode

Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the…

08.08.2007
Высокая CVSS 9.3

CVE-2007-4188

РасширениеJoomla Joomla\!
Разработчикsecunia

Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.

08.08.2007
Средняя CVSS 4.3

CVE-2007-4189

РасширениеJoomla Joomla\!
Разработчикosvdb

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) c…

08.08.2007
Средняя CVSS 4.3

CVE-2007-4190

РасширениеJoomla Joomla\!
Разработчикosvdb

CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF se…

08.08.2007
Высокая CVSS 7.5

CVE-2007-4128

РасширениеFirestorm Technologies Gmaps
Разработчикfirestorm-technologies

SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId p…

01.08.2007