Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla\! MEDIUM 6.1
CVE-2019-12766

An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS…

Fix: after 3.9.6
Fix from $1,600 2019-06-11
Joomla\! MEDIUM 6.1
CVE-2019-11809

An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential X…

Fix: 3.9.6+
Fix from $1,600 2019-05-20
Joomla\! CRITICAL 9.8
CVE-2019-10945EPSS 38%

An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to a…

Fix: after 3.9.4
Fix from $2,300 2019-04-10
Joomla\! HIGH 7.5
CVE-2019-10946

An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unaut…

Fix: after 3.9.4
Fix from $1,950 2019-04-10
Joomla\! HIGH 7.5
CVE-2019-9713

An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.

Fix: 3.9.4+
Fix from $1,950 2019-03-12
Joomla\! MEDIUM 6.1
CVE-2019-9711

An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.

Fix: 3.9.4+
Fix from $1,600 2019-03-12
Joomla\! MEDIUM 6.1
CVE-2019-9712

An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.

Fix: 3.9.4+
Fix from $1,600 2019-03-12
Joomla\! MEDIUM 6.1
CVE-2019-9714

An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.

Fix: 3.9.4+
Fix from $1,600 2019-03-12
Joomla\! CRITICAL 9.8
CVE-2019-7743

An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protectio…

Fix: after 3.9.2
Fix from $2,300 2019-02-12
Joomla\! MEDIUM 6.1
CVE-2019-7739

An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended…

Fix: after 3.9.2
Fix from $1,600 2019-02-12
Joomla\! MEDIUM 6.1
CVE-2019-7740

An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack…

Fix: after 3.9.2
Fix from $1,600 2019-02-12
Joomla\! MEDIUM 6.1
CVE-2019-7741

An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.

Fix: after 3.9.2
Fix from $1,600 2019-02-12
Joomla\! MEDIUM 6.1
CVE-2019-7742

An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and brow…

Fix: after 3.9.2
Fix from $1,600 2019-02-12
Joomla\! MEDIUM 6.1
CVE-2019-7744

An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.

Fix: after 3.9.2
Fix from $1,600 2019-02-12
Joomla\! MEDIUM 6.1
CVE-2019-6261

An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.

Fix: 3.9.2+
Fix from $1,600 2019-01-16
Joomla\! MEDIUM 6.1
CVE-2019-6264

An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.

Fix: 3.9.2+
Fix from $1,600 2019-01-16
Joomla\! MEDIUM 5.4
CVE-2019-6262

An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.

Fix: 3.9.2+
Fix from $1,600 2019-01-16
Joomla\! HIGH 8.8
CVE-2018-17855

An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in th…

Fix: 3.8.13+
Fix from $1,950 2018-10-09
Joomla\! HIGH 8.8
CVE-2018-17858

An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

Fix: 3.8.13+
Fix from $1,950 2018-10-09
Joomla\! HIGH 7.2
CVE-2018-17856

An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability…

Fix: 3.8.13+
Fix from $1,950 2018-10-09
Joomla\! CRITICAL 9.8
CVE-2018-15882

An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the…

Fix: 3.8.12+
Fix from $2,300 2018-08-29
Joomla\! HIGH 7.5
CVE-2018-15881

An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.

Fix: 3.8.12+
Fix from $1,950 2018-08-29
Joomla\! MEDIUM 5.4
CVE-2018-15880

An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.

Fix: 3.8.12+
Fix from $1,600 2018-08-29
Joomla\! HIGH 8.8
CVE-2018-12712

An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" functi…

Fix: after 3.8.8
Fix from $1,950 2018-06-26
Joomla\! MEDIUM 6.1
CVE-2018-12711

An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current langu…

Fix: after 3.8.8
Fix from $1,600 2018-06-26
Joomla\! CRITICAL 9.8
CVE-2018-11325

An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error…

Fix: 3.8.8+
Fix from $2,300 2018-05-22
Joomla\! HIGH 8.8
CVE-2018-11323

An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissi…

Fix: 3.8.8+
Fix from $1,950 2018-05-22
Joomla\! HIGH 7.5
CVE-2018-11322

An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by…

Fix: 3.8.8+
Fix from $1,950 2018-05-22
Joomla\! MEDIUM 6.5
CVE-2018-11321

An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulat…

Fix: 3.8.8+
Fix from $1,600 2018-05-22
Joomla\! MEDIUM 6.1
CVE-2018-6378

In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.

Fix: 3.8.8+
Fix from $1,600 2018-05-22