База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 180

Высокая CVSS 8.8

CVE-2017-20259

Разработчикjoomlashack

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter.…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20258

Разработчикextro.media

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code t…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20257

Разработчикjoomplace

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20256

Разработчикjoomplace

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invit…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20255

Разработчикjoombooking

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20254

Разработчикgegabyte

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the useri…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20253

Разработчикgegabyte

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerA…

19.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2017-20252

Разработчикexploit-db

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send…

19.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48907

РасширениеJCE
Разработчикjoomlacontenteditor

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

05.06.2026 Требует внимания
Высокая CVSS 7.1

CVE-2019-25740

Разработчикexploit-db

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send…

04.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25433

Разработчикjoomlaextensions.co.in

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through t…

01.06.2026 Требует внимания
Средняя CVSS 6.9

CVE-2026-48905

Разработчикjoomla

Lack of input filtering leads to an XSS vector in the HTML filter code.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-48903

Разработчикjoomla

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

26.05.2026 Активна
Высокая CVSS 8.2

CVE-2026-48904

Разработчикjoomla

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

26.05.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-48902

Разработчикjoomla

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48896

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48897

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-48901

Разработчикjoomla

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

26.05.2026 Требует внимания