CVE-2025-49486
A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.
Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.
A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.
A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
XSS vulnerability in DP Calendar component for Joomla.
SQLi vulnerability in Starshop component for Joomla.
SQLi vulnerability in S5 Register module for Joomla.
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
SQLi vulnerability in LMS Lite component for Joomla.
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.