База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 168

Высокая CVSS 7.1

CVE-2019-25740

Разработчикexploit-db

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send…

04.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25433

Разработчикjoomlaextensions.co.in

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through t…

01.06.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48904

Разработчикjoomla

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48898

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-48902

Разработчикjoomla

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

26.05.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-48901

Разработчикjoomla

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48897

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48896

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-40383

Разработчикjoomla

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

26.05.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-35223

Разработчикjoomla

An improper access check allows unauthorized access to com_config webservice endpoints.

26.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25381

Разработчикextro.media

Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers…

25.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25380

Разработчикextro.media

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, an…

25.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25351

Разработчикexploit-db

Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into t…

23.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25348

Разработчикexploit-db

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter…

23.05.2026 Требует внимания
Высокая CVSS 8.8

CVE-2018-25330

Разработчикexploit-db

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST para…

17.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2020-37226

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2020-37224

Разработчикjoomsky

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' para…

13.05.2026 Требует внимания
Высокая CVSS 8.7

CVE-2020-37219

Разработчикfabrikar

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send…

13.05.2026 Требует внимания