Vulnerability index

Browse CVEs

195 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Calendar Planner HIGH 8.2
CVE-2017-20267

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through…

No fix yet
Fix from $1,950 2026-06-19
Joomla\! MEDIUM 5.3
CVE-2022-27911

An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.

Mitigation only
Fix from $1,600 2022-08-31
Joomla\! CRITICAL 9.1
CVE-2021-26040

An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.

Mitigation only
Fix from $2,300 2021-08-24
Joomla\! CRITICAL 9.1
CVE-2011-1151

Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

No fix yet
Fix from $2,300 2020-02-05
Joomla\! HIGH 8.8
CVE-2019-14654

In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an un…

Mitigation only
Fix from $1,950 2019-08-05
Joomla\! CRITICAL 9.8
CVE-2017-14596EPSS 7%

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

No fix yet
Fix from $2,300 2017-09-20
Joomla\! MEDIUM 6.1
CVE-2015-5608

Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

Mitigation only
Fix from $1,600 2017-09-20
Joomla\! HIGH 8.8
CVE-2017-11364

The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control o…

Mitigation only
Fix from $1,950 2017-08-02
Joomla\! MEDIUM 6.1
CVE-2017-11612

In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.

Mitigation only
Fix from $1,600 2017-07-26
Joomla\! HIGH 7.5
CVE-2017-9933

Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.

Mitigation only
Fix from $1,950 2017-07-17
Joomla\! MEDIUM 6.1
CVE-2017-9934

Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.

Mitigation only
Fix from $1,600 2017-07-17
Joomla\! HIGH 7.3
CVE-2015-8769

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

Mitigation only
Fix from $1,950 2016-01-12
Session HIGH 7.5
CVE-2015-8566EPSS 8%

The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values.

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8565

Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknow…

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8564

Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences …

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! MEDIUM 6.8
CVE-2015-8563

Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote at…

Mitigation only
Fix from $1,600 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8562EPSS 98%

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP U…

No fix yet
Fix from $1,950 2015-12-16
Joomla\! MEDIUM 5.0
CVE-2015-7859

The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive informat…

Mitigation only
Fix from $1,600 2015-10-29
Joomla\! MEDIUM 5.0
CVE-2015-7899

The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via…

Mitigation only
Fix from $1,600 2015-10-29
Joomla\! HIGH 7.5
CVE-2015-7858EPSS 86%

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen…

No fix yet
Fix from $1,950 2015-10-29
Joomla\! HIGH 7.5
CVE-2015-7857EPSS 94%

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.…

No fix yet
Fix from $1,950 2015-10-29
Joomla\! HIGH 7.5
CVE-2015-7297EPSS 100%

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen…

No fix yet
Fix from $1,950 2015-10-29
Joomla\! MEDIUM 6.8
CVE-2015-5397

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2015-07-14
Joomla\! HIGH 7.5
CVE-2015-4654

SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id param…

No fix yet
Fix from $1,950 2015-06-18
Joomla\! HIGH 7.5
CVE-2014-7228EPSS 55%

Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi…

No fix yet
Fix from $1,950 2014-11-03
Joomla\! HIGH 7.5
CVE-2014-7981EPSS 9%

SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

Mitigation only
Fix from $1,950 2014-10-08
Joomla\! HIGH 7.5
CVE-2014-7984

Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving G…

Mitigation only
Fix from $1,950 2014-10-08
Joomla\! HIGH 7.5
CVE-2014-6632

Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions…

Mitigation only
Fix from $1,950 2014-10-08
Joomla\! MEDIUM 5.0
CVE-2014-7229

Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of servi…

No fix yet
Fix from $1,600 2014-10-08
Joomla\! MEDIUM 5.5
CVE-2013-3242

plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializi…

No fix yet
Fix from $1,600 2013-05-03