Каталог CVE

Разработчик: github

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 23

Разработчик: github
Средняя CVSS 6.1

CVE-2025-55757

РасширениеVirtueMart
Разработчикgithub

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

25.10.2025
Высокая CVSS 8.7

CVE-2025-54475

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

15.08.2025
Высокая CVSS 8.7

CVE-2025-49484

Расширениеthe JS Jobs plugin versions
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee app…

18.07.2025
Низкая CVSS 3.8

CVE-2025-25228

РасширениеVirtuemart Virtuemart
Разработчикgithub

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

21.04.2025
Средняя CVSS 6.5

CVE-2025-25225

РасширениеHikashop Hikashop
Разработчикgithub

A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Per…

15.03.2025
Низкая CVSS 2.7

CVE-2025-22212

Разработчикgithub

A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the…

05.03.2025
Низкая CVSS 3.4

CVE-2025-22211

РасширениеWebdesigner-profi Joomshopping
Разработчикgithub

A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country m…

25.02.2025
Высокая CVSS 7.2

CVE-2025-22210

РасширениеHikashop Hikashop
Разработчикgithub

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category mana…

25.02.2025
Средняя CVSS 4.7

CVE-2025-22209

РасширениеJoomsky Js Jobs
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentst…

15.02.2025
Средняя CVSS 4.7

CVE-2025-22208

РасширениеJoomsky Js Jobs
Разработчикgithub

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' p…

15.02.2025
Критическая CVSS 9.3

CVE-2024-11145

Разработчикgithub

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! applicati…

26.11.2024
Средняя CVSS 6.1

CVE-2024-21728

РасширениеSmartcalc Osticky
Разработчикgithub

An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a…

15.02.2024
Средняя CVSS 6.5

CVE-2023-28732

РасширениеAcymailing Acymailing
Разработчикgithub

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, whe…

30.03.2023
Средняя CVSS 5.5

CVE-2010-10003

РасширениеTitlelink Project Titlelink
Разработчикgithub

A vulnerability classified as critical was found in gesellix titlelink on Joomla. Affected by this vulnerability is an unknown functionality of the file plugin_content_title.php. The manipu…

04.01.2023
Критическая CVSS 9.8

CVE-2019-19634

РасширениеVerot Project Verot
Разработчикgithub

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensi…

17.12.2019
Средняя CVSS 6.1

CVE-2018-10727

РасширениеFabrikar Fabrik
Разработчикgithub

Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrar…

29.10.2019
Средняя CVSS 5.4

CVE-2019-15120

РасширениеKunena Kunena
Разработчикgithub

The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

16.08.2019