База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
53за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Высокая CVSS 8.2

CVE-2026-48898

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Требует внимания
Средняя CVSS 5.3

CVE-2026-48899

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Активна
Средняя CVSS 6.4

CVE-2026-48900

Разработчикjoomla

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

26.05.2026 Активна
Средняя CVSS 5.9

CVE-2026-40384

Разработчикjoomla

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

26.05.2026 Активна
Высокая CVSS 7.5

CVE-2026-40383

Разработчикjoomla

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

26.05.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-35223

Разработчикjoomla

An improper access check allows unauthorized access to com_config webservice endpoints.

26.05.2026 Требует внимания
Средняя CVSS 4.6

CVE-2026-35220

Разработчикjoomla

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-35221

Разработчикjoomla

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-35222

Разработчикjoomla

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-30895

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-25900

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the feed modules.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-25901

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the multilingual associations component.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-30894

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the content history component.

26.05.2026 Активна
Высокая CVSS 7.1

CVE-2018-25381

Разработчикextro.media

Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers…

25.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25380

Разработчикextro.media

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, an…

25.05.2026 Требует внимания
Средняя CVSS 5.3

CVE-2018-25354

Разработчикexploit-db

Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting mal…

23.05.2026 Активна
Высокая CVSS 8.8

CVE-2018-25351

Разработчикexploit-db

Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into t…

23.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25348

Разработчикexploit-db

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter…

23.05.2026 Требует внимания