Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla\! HIGH 7.5
CVE-2015-8565

Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknow…

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8564

Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences …

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! MEDIUM 6.8
CVE-2015-8563

Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote at…

Mitigation only
Fix from $1,600 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8562EPSS 98%

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP U…

No fix yet
Fix from $1,950 2015-12-16
Joomla\! MEDIUM 5.0
CVE-2015-7859

The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive informat…

Mitigation only
Fix from $1,600 2015-10-29
Joomla\! MEDIUM 5.0
CVE-2015-7899

The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via…

Mitigation only
Fix from $1,600 2015-10-29
Joomla\! HIGH 7.5
CVE-2015-7858EPSS 86%

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen…

No fix yet
Fix from $1,950 2015-10-29
Joomla\! HIGH 7.5
CVE-2015-7857EPSS 94%

SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.…

No fix yet
Fix from $1,950 2015-10-29
Joomla\! HIGH 7.5
CVE-2015-7297EPSS 100%

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen…

No fix yet
Fix from $1,950 2015-10-29
Joomla\! MEDIUM 6.8
CVE-2015-5397

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2015-07-14
Joomla\! HIGH 7.5
CVE-2015-4654

SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id param…

No fix yet
Fix from $1,950 2015-06-18
Joomla\! HIGH 7.5
CVE-2014-7228EPSS 55%

Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi…

No fix yet
Fix from $1,950 2014-11-03
Joomla\! HIGH 7.5
CVE-2014-7981EPSS 9%

SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

Mitigation only
Fix from $1,950 2014-10-08
Joomla\! HIGH 7.5
CVE-2014-7984

Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving G…

Mitigation only
Fix from $1,950 2014-10-08
Joomla\! HIGH 7.5
CVE-2014-6632

Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions…

Mitigation only
Fix from $1,950 2014-10-08
Joomla\! MEDIUM 5.0
CVE-2014-7229

Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of servi…

No fix yet
Fix from $1,600 2014-10-08
Joomla\! MEDIUM 6.8
CVE-2013-5576EPSS 48%

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authentic…

Patch available
Fix from $1,600 2013-10-09
Joomla\! MEDIUM 5.5
CVE-2013-3242

plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializi…

No fix yet
Fix from $1,600 2013-05-03
Joomla\! HIGH 7.5
CVE-2013-1453

plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects t…

No fix yet
Fix from $1,950 2013-02-13
Joomla\! MEDIUM 5.0
CVE-2013-1454

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors."

No fix yet
Fix from $1,600 2013-02-13
Joomla\! MEDIUM 5.0
CVE-2013-1455

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable."

Mitigation only
Fix from $1,600 2013-02-13
Joomla\! HIGH 7.5
CVE-2012-1598

Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."

Mitigation only
Fix from $1,950 2012-12-03
Joomla\! MEDIUM 5.0
CVE-2012-1599

Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via…

Mitigation only
Fix from $1,600 2012-12-03
Joomla\! MEDIUM 5.0
CVE-2011-4911

Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecif…

Fix: after 1.5.11
Fix from $1,600 2012-10-07
Joomla\! HIGH 7.5
CVE-2012-1116

SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Mitigation only
Fix from $1,950 2012-09-26
Joomla\! MEDIUM 5.0
CVE-2012-1611

Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via …

Mitigation only
Fix from $1,600 2012-09-06
Joomla\! MEDIUM 5.0
CVE-2012-0819

Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a diff…

Patch available
Fix from $1,600 2012-09-06
Joomla\! MEDIUM 5.0
CVE-2012-0821

Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a diff…

Patch available
Fix from $1,600 2012-09-06
Joomla\! MEDIUM 5.0
CVE-2012-0835

Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain sensitive information via unknown vectors r…

Patch available
Fix from $1,600 2012-09-06
Joomla\! MEDIUM 5.0
CVE-2012-0836

Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors.

Patch available
Fix from $1,600 2012-09-06