Vulnerability index

Browse CVEs

195 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2017-20267 Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through… Calendar Planner No fix yet Fix from $1,9502026-06-19 MEDIUM 5.3 CVE-2022-27911 An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. Joomla\! Mitigation only Fix from $1,6002022-08-31 CRITICAL 9.1 CVE-2021-26040 An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command. Joomla\! Mitigation only Fix from $2,3002021-08-24 CRITICAL 9.1 CVE-2011-1151 Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. Joomla\! No fix yet Fix from $2,3002020-02-05 HIGH 8.8 CVE-2019-14654 In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an un… Joomla\! Mitigation only Fix from $1,9502019-08-05 CRITICAL 9.8 CVE-2017-14596EPSS 7% In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. Joomla\! No fix yet Fix from $2,3002017-09-20 MEDIUM 6.1 CVE-2015-5608 Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1. Joomla\! Mitigation only Fix from $1,6002017-09-20 HIGH 8.8 CVE-2017-11364 The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control o… Joomla\! Mitigation only Fix from $1,9502017-08-02 MEDIUM 6.1 CVE-2017-11612 In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components. Joomla\! Mitigation only Fix from $1,6002017-07-26 HIGH 7.5 CVE-2017-9933 Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. Joomla\! Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-9934 Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability. Joomla\! Mitigation only Fix from $1,6002017-07-17 HIGH 7.3 CVE-2015-8769 SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors. Joomla\! Mitigation only Fix from $1,9502016-01-12 HIGH 7.5 CVE-2015-8566EPSS 8% The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values. Session Mitigation only Fix from $1,9502015-12-16 HIGH 7.5 CVE-2015-8565 Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknow… Joomla\! Mitigation only Fix from $1,9502015-12-16 HIGH 7.5 CVE-2015-8564 Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences … Joomla\! Mitigation only Fix from $1,9502015-12-16 MEDIUM 6.8 CVE-2015-8563 Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote at… Joomla\! Mitigation only Fix from $1,6002015-12-16 HIGH 7.5 CVE-2015-8562EPSS 98% Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP U… Joomla\! No fix yet Fix from $1,9502015-12-16 MEDIUM 5.0 CVE-2015-7859 The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive informat… Joomla\! Mitigation only Fix from $1,6002015-10-29 MEDIUM 5.0 CVE-2015-7899 The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via… Joomla\! Mitigation only Fix from $1,6002015-10-29 HIGH 7.5 CVE-2015-7858EPSS 86% SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen… Joomla\! No fix yet Fix from $1,9502015-10-29 HIGH 7.5 CVE-2015-7857EPSS 94% SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.… Joomla\! No fix yet Fix from $1,9502015-10-29 HIGH 7.5 CVE-2015-7297EPSS 100% SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen… Joomla\! No fix yet Fix from $1,9502015-10-29 MEDIUM 6.8 CVE-2015-5397 Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentic… Joomla\! Mitigation only Fix from $1,6002015-07-14 HIGH 7.5 CVE-2015-4654 SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id param… Joomla\! No fix yet Fix from $1,9502015-06-18 HIGH 7.5 CVE-2014-7228EPSS 55% Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi… Joomla\! No fix yet Fix from $1,9502014-11-03 HIGH 7.5 CVE-2014-7981EPSS 9% SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vec… Joomla\! Mitigation only Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-7984 Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving G… Joomla\! Mitigation only Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-6632 Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions… Joomla\! Mitigation only Fix from $1,9502014-10-08 MEDIUM 5.0 CVE-2014-7229 Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of servi… Joomla\! No fix yet Fix from $1,6002014-10-08 MEDIUM 5.5 CVE-2013-3242 plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializi… Joomla\! No fix yet Fix from $1,6002013-05-03