Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla\! CRITICAL 9.1
CVE-2021-23128

An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an po…

Fix: 3.9.25+
Fix from $2,300 2021-03-04
Joomla\! HIGH 7.5
CVE-2021-23131

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.

Fix: 3.9.25+
Fix from $1,950 2021-03-04
Joomla\! HIGH 7.5
CVE-2021-23132EPSS 7%

An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads

Fix: 3.9.25+
Fix from $1,950 2021-03-04
Joomla\! MEDIUM 6.1
CVE-2021-23129

An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Joomla\! MEDIUM 6.1
CVE-2021-23130

An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Joomla\! MEDIUM 5.5
CVE-2021-26028

An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Joomla\! MEDIUM 5.3
CVE-2021-23126

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Joomla\! MEDIUM 5.3
CVE-2021-26027

An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Joomla\! MEDIUM 5.3
CVE-2021-26029

An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Joomla\! MEDIUM 6.1
CVE-2021-23124EPSS 81%

An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

Fix: after 3.9.23
Fix from $1,600 2021-01-12
Joomla\! MEDIUM 6.1
CVE-2021-23125

An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XS…

Fix: after 3.9.23
Fix from $1,600 2021-01-12
Joomla\! MEDIUM 5.3
CVE-2021-23123

An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublishe…

Fix: after 3.9.23
Fix from $1,600 2021-01-12
Joomla\! HIGH 7.5
CVE-2020-35616EPSS 6%

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

Fix: after 3.9.22
Fix from $1,950 2020-12-28
Joomla\! CRITICAL 9.8
CVE-2020-35613EPSS 29%

An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backen…

Fix: after 3.9.22
Fix from $2,300 2020-12-28
Joomla\! HIGH 7.5
CVE-2020-35610

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the correspondi…

Fix: after 3.9.22
Fix from $1,950 2020-12-28
Joomla\! HIGH 7.5
CVE-2020-35611

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the …

Fix: after 3.9.22
Fix from $1,950 2020-12-28
Joomla\! HIGH 7.5
CVE-2020-35612

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversa…

Fix: after 3.9.22
Fix from $1,950 2020-12-28
Joomla\! MEDIUM 6.3
CVE-2020-35615

An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.

Fix: after 3.9.22
Fix from $1,600 2020-12-28
Joomla\! MEDIUM 5.3
CVE-2020-35614

An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend l…

Fix: after 3.9.22
Fix from $1,600 2020-12-28
Joomla\! MEDIUM 6.1
CVE-2020-24599

An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.

Fix: 3.9.21+
Fix from $1,600 2020-08-26
Joomla\! MEDIUM 6.1
CVE-2020-24598

An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

Fix: 3.9.21+
Fix from $1,600 2020-08-26
Joomla\! MEDIUM 6.3
CVE-2020-15695

An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Joomla\! MEDIUM 6.3
CVE-2020-15700

An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Joomla\! MEDIUM 6.1
CVE-2020-15696

An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Joomla\! MEDIUM 5.3
CVE-2020-15698

An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Joomla\! MEDIUM 5.3
CVE-2020-15699

An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.

Fix: after 3.9.19
Fix from $1,600 2020-07-15
Joomla\! HIGH 8.8
CVE-2020-13760

In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

Fix: 3.9.19+
Fix from $1,950 2020-06-02
Joomla\! HIGH 7.5
CVE-2020-13763

In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.

Fix: 3.9.19+
Fix from $1,950 2020-06-02
Joomla\! MEDIUM 6.1
CVE-2020-13761

In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows…

Fix: 3.9.19+
Fix from $1,600 2020-06-02
Joomla\! MEDIUM 6.1
CVE-2020-13762

In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.

Fix: 3.9.19+
Fix from $1,600 2020-06-02