Каталог CVE

Разработчик: developer.joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 159

Разработчик: developer.joomla
Средняя CVSS 4.3

CVE-2009-1940

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script o…

05.06.2009
Средняя CVSS 4.3

CVE-2009-1939

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

05.06.2009
Средняя CVSS 4.3

CVE-2009-1938

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output an…

05.06.2009
Средняя CVSS 6.8

CVE-2009-1280

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified vict…

09.04.2009
Низкая CVSS 2.6

CVE-2009-1279

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin c…

09.04.2009
Низкая CVSS 3.5

CVE-2008-6299

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the…

26.02.2009
Высокая CVSS 7.5

CVE-2008-4105

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecif…

18.09.2008
Средняя CVSS 5.8

CVE-2008-4104

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.

18.09.2008
Средняя CVSS 5.0

CVE-2008-4103

РасширениеJoomla Com Mailto
Разработчикdeveloper.joomla

The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.

18.09.2008
Высокая CVSS 7.5

CVE-2008-4102

РасширениеJoomla Joomla
Разработчикdeveloper.joomla

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated b…

18.09.2008
Высокая CVSS 7.5

CVE-2008-3681

РасширениеJoomla Com User
Разработчикdeveloper.joomla

components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" passwo…

14.08.2008
Высокая CVSS 7.5

CVE-2006-7124

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute…

06.03.2007
Средняя CVSS 6.8

CVE-2006-7126

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.

06.03.2007
Высокая CVSS 7.5

CVE-2006-4995

РасширениеJoomla Bsq Sitestats
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in BSQ Sitestats (bsq_sitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_p…

26.09.2006
Высокая CVSS 7.5

CVE-2006-3970

РасширениеJoomla Lmo
Разработчикdeveloper.joomla

PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosCon…

01.08.2006