Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla MEDIUM 6.8
CVE-2009-1280

Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijac…

Mitigation only
Fix from $1,600 2009-04-09
Com Mycontent HIGH 7.5
CVE-2008-6430

SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands v…

No fix yet
Fix from $1,950 2009-03-06
Com Musica HIGH 7.5
CVE-2008-6234

SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parame…

No fix yet
Fix from $1,950 2009-02-21
Ignitegallery HIGH 7.5
CVE-2008-6182

SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2009-02-19
Com Eventing HIGH 7.5
CVE-2009-0421

SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via …

No fix yet
Fix from $1,950 2009-02-05
Com Beamospetition HIGH 7.5
CVE-2009-0377

SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL …

No fix yet
Fix from $1,950 2009-02-02
Com Pcchess HIGH 7.5
CVE-2009-0379

SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL comman…

No fix yet
Fix from $1,950 2009-02-02
Com Pccookbook HIGH 7.5
CVE-2009-0329

SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via th…

No fix yet
Fix from $1,950 2009-01-29
Com Waticketsystem HIGH 7.5
CVE-2009-0333

SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2009-01-29
Xstandard MEDIUM 5.0
CVE-2009-0113EPSS 7%

Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list a…

No fix yet
Fix from $1,600 2009-01-09
Com Paxgallery HIGH 7.5
CVE-2008-5811

SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands vi…

No fix yet
Fix from $1,950 2009-01-02
Joomla\! HIGH 7.5
CVE-2008-4122

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this coo…

Mitigation only
Fix from $1,950 2008-12-19
Joomla HIGH 7.5
CVE-2008-5671

PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remo…

Fix: after 1.0.14
Fix from $1,950 2008-12-19
Com Books HIGH 7.5
CVE-2008-5643

SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id …

No fix yet
Fix from $1,950 2008-12-17
Com Datsogallery HIGH 7.5
CVE-2008-5208

SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbit…

No fix yet
Fix from $1,950 2008-11-24
Com Xewebtv HIGH 7.5
CVE-2008-5200

SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id …

No fix yet
Fix from $1,950 2008-11-21
Com Rssreader HIGH 10.0
CVE-2008-5053EPSS 63%

PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attac…

No fix yet
Fix from $1,950 2008-11-13
Com Lms HIGH 7.5
CVE-2008-4777

SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL …

Patch available
Fix from $1,950 2008-10-29
Com Imagebrowser HIGH 9.0
CVE-2008-4668EPSS 21%

Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute …

No fix yet
Fix from $1,950 2008-10-22
Joomla HIGH 7.5
CVE-2008-4102

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by P…

Mitigation only
Fix from $1,950 2008-09-18
Joomla HIGH 7.5
CVE-2008-4105

JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "varia…

Mitigation only
Fix from $1,950 2008-09-18
Joomla MEDIUM 5.8
CVE-2008-4104

Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishi…

Mitigation only
Fix from $1,600 2008-09-18
Com Mailto MEDIUM 5.0
CVE-2008-4103

The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to …

Mitigation only
Fix from $1,600 2008-09-18
Com User HIGH 7.5
CVE-2008-3681EPSS 9%

components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the…

No fix yet
Fix from $1,950 2008-08-14
Com Ezstore HIGH 7.5
CVE-2008-3586

SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id …

No fix yet
Fix from $1,950 2008-08-11
Com Dtregister MEDIUM 6.8
CVE-2008-3265

SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands…

No fix yet
Fix from $1,600 2008-07-24
Joomla HIGH 10.0
CVE-2008-3225

Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP …

Fix: after 1.5.3
Fix from $1,950 2008-07-18
Joomla HIGH 7.5
CVE-2008-3227

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redir…

Fix: after 1.5.3
Fix from $1,950 2008-07-18
Joomla HIGH 7.5
CVE-2008-3228

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact…

Fix: after 1.5.3
Fix from $1,950 2008-07-18
Joomla MEDIUM 5.0
CVE-2008-3226

The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

Fix: after 1.5.3
Fix from $1,600 2008-07-18