База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 7.5

CVE-2006-4320

РасширениеOpensef Project Opensef
Разработчикsecuritytracker

PHP remote file inclusion vulnerability in sef.php in the OpenSEF 2.0.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path…

24.08.2006
Высокая CVSS 7.5

CVE-2006-4282

РасширениеMamboxchange Mambowiki
Разработчикsecurityreason

PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP…

22.08.2006
Высокая CVSS 7.5

CVE-2006-4263

Разработчикosvdb

Multiple PHP remote file inclusion vulnerabilities in the Product Scroller Module and other modules in mambo-phpshop (com_phpshop) for Mambo and Joomla! allow remote attackers to execute ar…

21.08.2006
Высокая CVSS 7.5

CVE-2006-4269

РасширениеJoomla X-shop Component
Разработчикarchives.neohapsis

PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code…

21.08.2006
Средняя CVSS 5.1

CVE-2006-4242

Разработчикsecunia

PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_ab…

21.08.2006
Высокая CVSS 7.5

CVE-2006-4229

Разработчикblog.phil-taylor

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code…

18.08.2006
Высокая CVSS 7.5

CVE-2006-4129

РасширениеJoomla Webring Component
Разработчикsecunia

PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code vi…

14.08.2006
Средняя CVSS 6.8

CVE-2006-4130

Разработчикsecunia

PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabled, allows…

14.08.2006
Средняя CVSS 6.8

CVE-2006-4074

РасширениеJoomla Jd-wiki
Разработчикsecunia

PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote att…

11.08.2006
Высокая CVSS 7.5

CVE-2006-3990

РасширениеPhpsavant Savant2
Разработчикsecurityreason

Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitra…

05.08.2006
Средняя CVSS 6.8

CVE-2006-3995

Разработчикattrition

Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, a…

05.08.2006
Высокая CVSS 7.5

CVE-2006-3969

РасширениеJoomla Colophon
Разработчикsecunia

PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP…

01.08.2006
Высокая CVSS 7.5

CVE-2006-3970

РасширениеJoomla Lmo
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosCon…

01.08.2006
Средняя CVSS 6.8

CVE-2006-3773

РасширениеMambo Smf-forum
Разработчикforum.mamboserver

PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via…

24.07.2006
Средняя CVSS 6.8

CVE-2006-3774

РасширениеJoomla Performs Component
Разработчикsecunia

PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL…

24.07.2006
Средняя CVSS 6.8

CVE-2006-3750

РасширениеHashcash Hashcash
Разработчикadvisories.echo.or.id

PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosCo…

21.07.2006
Средняя CVSS 6.8

CVE-2006-3530

РасширениеJoomla Pc Cookbook
Разработчикadvisories.echo.or.id

PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, all…

12.07.2006
Средняя CVSS 5.8

CVE-2006-3480

РасширениеJoomla Joomla
Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUs…

10.07.2006