База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 7.5

CVE-2006-4269

РасширениеJoomla X-shop Component
Разработчикarchives.neohapsis

PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code…

21.08.2006
Средняя CVSS 5.1

CVE-2006-4242

Разработчикsecunia

PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_ab…

21.08.2006
Высокая CVSS 7.5

CVE-2006-4229

Разработчикblog.phil-taylor

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code…

18.08.2006
Высокая CVSS 7.5

CVE-2006-4129

РасширениеJoomla Webring Component
Разработчикsecunia

PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code vi…

14.08.2006
Средняя CVSS 6.8

CVE-2006-4130

Разработчикsecunia

PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabled, allows…

14.08.2006
Средняя CVSS 6.8

CVE-2006-4074

РасширениеJoomla Jd-wiki
Разработчикsecunia

PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote att…

11.08.2006
Высокая CVSS 7.5

CVE-2006-3990

РасширениеPhpsavant Savant2
Разработчикsecurityreason

Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitra…

05.08.2006
Средняя CVSS 6.8

CVE-2006-3995

Разработчикattrition

Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, a…

05.08.2006
Высокая CVSS 7.5

CVE-2006-3969

РасширениеJoomla Colophon
Разработчикsecunia

PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP…

01.08.2006
Высокая CVSS 7.5

CVE-2006-3970

РасширениеJoomla Lmo
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosCon…

01.08.2006
Средняя CVSS 6.8

CVE-2006-3773

РасширениеMambo Smf-forum
Разработчикforum.mamboserver

PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via…

24.07.2006
Средняя CVSS 6.8

CVE-2006-3774

РасширениеJoomla Performs Component
Разработчикsecunia

PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL…

24.07.2006
Средняя CVSS 6.8

CVE-2006-3750

РасширениеHashcash Hashcash
Разработчикadvisories.echo.or.id

PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosCo…

21.07.2006
Средняя CVSS 6.8

CVE-2006-3530

РасширениеJoomla Pc Cookbook
Разработчикadvisories.echo.or.id

PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, all…

12.07.2006
Средняя CVSS 5.8

CVE-2006-3480

РасширениеJoomla Joomla
Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUs…

10.07.2006
Высокая CVSS 7.5

CVE-2006-3481

РасширениеJoomla Joomla
Разработчикsecunia

Multiple SQL injection vulnerabilities in Joomla! before 1.0.10 allow remote attackers to execute arbitrary SQL commands via unspecified parameters involving the (1) "Remember Me" function,…

10.07.2006
Высокая CVSS 7.5

CVE-2006-2960

РасширениеJoomla Joomla
Разработчикsecurityreason

PHP remote file inclusion vulnerability in includes/joomla.php in Joomla! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.

12.06.2006
Средняя CVSS 6.8

CVE-2006-2815

Разработчикlists.grok.org.uk

Multiple cross-site scripting (XSS) vulnerabilities in Two Shoes M-Factory (TSMF) SimpleBoard 1.1.0 Stable (aka com_simpleboard), as used in Mambo and Joomla!, allow remote attackers to inj…

05.06.2006