База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 169

Критическая CVSS 9.8

CVE-2018-5984

РасширениеTumder Project Tumder
Разработчикexploit-db

SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.

24.01.2018
Критическая CVSS 9.8

CVE-2018-5696

РасширениеIjoomla Ad Agency
Разработчикvulnerability-lab

The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php.

14.01.2018
Критическая CVSS 9.8

CVE-2017-17875

РасширениеJextn Jextn Faq Pro
Разработчикexploit-db

The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17872

РасширениеJextn Jextn Video Gallery
Разработчикexploit-db

The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17871

Разработчикexploit-db

The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

27.12.2017
Критическая CVSS 9.8

CVE-2017-17870

РасширениеJbuildozer Jbuildozer
Разработчикvel.joomla

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

27.12.2017
Критическая CVSS 9.8

CVE-2017-16634

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

10.11.2017
Критическая CVSS 9.8

CVE-2017-15965

РасширениеNswd Ns Download Shop
Разработчикsecurityfocus

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

29.10.2017
Критическая CVSS 9.8

CVE-2017-15946

РасширениеSelfget Tag Meta
Разработчикsecurityfocus

In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.

28.10.2017
Критическая CVSS 9.8

CVE-2017-14596

РасширениеJoomla Joomla\!
Разработчикjoomla

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

20.09.2017
Критическая CVSS 9.8

CVE-2015-4073

Разработчикpacketstormsecurity

Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email para…

20.09.2017
Критическая CVSS 9.8

CVE-2013-7429

РасширениеMapsplugin Googlemaps
Разработчикseclists

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

14.09.2017
Критическая CVSS 9.8

CVE-2015-2798

РасширениеWeb-dorado Contact Form Maker
Разработчикsecurityfocus

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

25.07.2017
Критическая CVSS 9.8

CVE-2017-8917

РасширениеJoomla Joomla\!
Разработчикjoomla

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

17.05.2017
Критическая CVSS 9.8

CVE-2017-5215

РасширениеCodextrous B2j Contact
Разработчикnavixia

The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechanism, leading to remote code ex…

17.05.2017
Критическая CVSS 9.8

CVE-2016-9081

РасширениеJoomla Joomla\!
Разработчикjoomla

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

23.01.2017