База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 168

Высокая CVSS 8.8

CVE-2017-20268

Разработчикexploit-db

Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20267

РасширениеJoomla Calendar Planner
Разработчикjoomla

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers ca…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20266

РазработчикJoomShaper

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchwor…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2017-20265

РасширениеPulseextensions Flip Wall
Разработчикpulseextensions

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid…

19.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2017-20264

РасширениеPulseextensions Sponsor Wall
Разработчикpulseextensions

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wal…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20263

РасширениеFocalpointx Focalpoint
Разработчикfocalpointx

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20262

РасширениеWebkul Ajax Quiz
Разработчикwebkul

Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid pa…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20261

РасширениеWeborange Bargain Product Vm3
Разработчикexploit-db

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20260

РасширениеWeborange Price Alert
Разработчикexploit-db

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the pr…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20259

РасширениеJoomlashack Osdownloads
Разработчикjoomlashack

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter.…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20258

РасширениеExtro Responsive Portfolio
Разработчикextro.media

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code t…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20257

РасширениеJoomplace Quiz Deluxe
Разработчикjoomplace

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20256

РасширениеJoomplace Survey Force Deluxe
Разработчикjoomplace

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invit…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20255

РасширениеJoombooking Jb Visa
Разработчикjoombooking

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20254

РасширениеGegabyte User Bench
Разработчикgegabyte

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the useri…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20253

РасширениеGegabyte My Projects
Разработчикgegabyte

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerA…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20252

РасширениеNextgeneditor Nextgen Editor
Разработчикexploit-db

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send…

19.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48907

РасширениеJCE
Разработчикjoomlacontenteditor

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

05.06.2026 Требует внимания