Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla\! MEDIUM 5.9
CVE-2018-11324

An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could c…

Fix: 3.8.8+
Fix from $1,600 2018-05-22
Joomla\! HIGH 8.8
CVE-2018-8045EPSS 29%

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes li…

Fix: after 3.8.5
Fix from $1,950 2018-03-15
Joomla\! CRITICAL 9.8
CVE-2018-6376

In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall m…

Fix: 3.8.4+
Fix from $2,300 2018-01-30
Joomla\! MEDIUM 6.1
CVE-2018-6377EPSS 57%

In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and check…

Fix: 3.8.4+
Fix from $1,600 2018-01-30
Joomla\! MEDIUM 6.1
CVE-2018-6379

In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.

Fix: 3.8.4+
Fix from $1,600 2018-01-30
Joomla\! MEDIUM 6.1
CVE-2018-6380

In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.

Fix: 3.8.4+
Fix from $1,600 2018-01-30
Joomla\! CRITICAL 9.8
CVE-2017-16634

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

Fix: after 3.8.1
Fix from $2,300 2017-11-10
Joomla\! CRITICAL 9.8
CVE-2017-14596EPSS 7%

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

No fix yet
Fix from $2,300 2017-09-20
Joomla\! MEDIUM 6.1
CVE-2015-5608

Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

Mitigation only
Fix from $1,600 2017-09-20
Joomla\! HIGH 8.8
CVE-2017-11364

The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control o…

Mitigation only
Fix from $1,950 2017-08-02
Joomla\! MEDIUM 6.1
CVE-2017-11612

In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.

Mitigation only
Fix from $1,600 2017-07-26
Joomla\! HIGH 7.5
CVE-2017-9933

Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.

Mitigation only
Fix from $1,950 2017-07-17
Joomla\! MEDIUM 6.1
CVE-2017-9934

Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.

Mitigation only
Fix from $1,600 2017-07-17
Joomla\! CRITICAL 9.8
CVE-2017-8917EPSS 100%

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

Patch available
Fix from $2,300 2017-05-17
Joomla\! MEDIUM 6.5
CVE-2017-7989

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explic…

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 6.1
CVE-2017-7984

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 6.1
CVE-2017-7985

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.

Fix: after 3.6.5
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 6.1
CVE-2017-7986

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 6.1
CVE-2017-7987

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager co…

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 5.3
CVE-2017-7983

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 5.3
CVE-2017-7988

In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 5.3
CVE-2017-8057

In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.

Patch available
Fix from $1,600 2017-04-25
Joomla\! CRITICAL 9.8
CVE-2016-9081

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifica…

Patch available
Fix from $2,300 2017-01-23
Joomla\! HIGH 7.5
CVE-2016-9837

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 l…

Fix: after 3.6.4
Fix from $1,950 2016-12-16
Joomla\! HIGH 7.5
CVE-2016-9838EPSS 14%

An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored…

Fix: after 3.6.4
Fix from $1,950 2016-12-16
Joomla\! CRITICAL 9.8
CVE-2016-9836

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking…

Fix: after 3.6.4
Fix from $2,300 2016-12-05
Joomla\! HIGH 8.1
CVE-2016-8870EPSS 81%

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has…

Fix: after 3.6.3
Fix from $1,950 2016-11-04
Joomla\! CRITICAL 9.8
CVE-2016-8869EPSS 97%

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attacker…

Fix: after 3.6.3
Fix from $2,300 2016-11-04
Joomla\! HIGH 7.3
CVE-2015-8769

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

Mitigation only
Fix from $1,950 2016-01-12
Session HIGH 7.5
CVE-2015-8566EPSS 8%

The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values.

Mitigation only
Fix from $1,950 2015-12-16