Каталог CVE

Разработчик: developer.joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 149

Разработчик: developer.joomla
Средняя CVSS 4.3

CVE-2011-2509

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact compone…

27.07.2011
Средняя CVSS 5.0

CVE-2011-2488

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.

27.07.2011
Высокая CVSS 7.5

CVE-2010-4696

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via the (1) filter_order or (2) filter_order_Dir parameter in…

18.01.2011
Средняя CVSS 4.3

CVE-2010-3712

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple…

28.10.2010
Низкая CVSS 3.5

CVE-2010-2535

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator…

05.10.2010
Средняя CVSS 4.3

CVE-2010-1649

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related t…

08.06.2010
Средняя CVSS 5.0

CVE-2009-3946

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.

16.11.2009
Средняя CVSS 5.5

CVE-2009-3945

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of…

16.11.2009
Средняя CVSS 4.3

CVE-2009-1940

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script o…

05.06.2009
Средняя CVSS 4.3

CVE-2009-1939

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

05.06.2009
Средняя CVSS 4.3

CVE-2009-1938

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output an…

05.06.2009
Средняя CVSS 6.8

CVE-2009-1280

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified vict…

09.04.2009
Низкая CVSS 2.6

CVE-2009-1279

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin c…

09.04.2009
Низкая CVSS 3.5

CVE-2008-6299

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the…

26.02.2009
Высокая CVSS 7.5

CVE-2008-4105

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecif…

18.09.2008
Средняя CVSS 5.8

CVE-2008-4104

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.

18.09.2008
Средняя CVSS 5.0

CVE-2008-4103

РасширениеJoomla Com Mailto
Разработчикdeveloper.joomla

The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.

18.09.2008
Высокая CVSS 7.5

CVE-2008-4102

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated b…

18.09.2008