Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla\! MEDIUM 5.0
CVE-2012-0837

Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."

Patch available
Fix from $1,600 2012-09-06
Com Weblinks HIGH 7.5
CVE-2006-7247

SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbit…

Fix: after 1.0.9
Fix from $1,950 2012-09-06
Joomla\! MEDIUM 5.0
CVE-2012-3829

Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.

No fix yet
Fix from $1,600 2012-07-03
Joomla\! HIGH 7.5
CVE-2012-2747

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate …

No fix yet
Fix from $1,950 2012-07-03
Joomla\! MEDIUM 5.0
CVE-2012-2748

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate fi…

Mitigation only
Fix from $1,600 2012-07-03
Joomla\! MEDIUM 5.0
CVE-2011-4321

The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the p…

Mitigation only
Fix from $1,600 2011-11-23
Com Elite Experts HIGH 7.5
CVE-2010-4944

SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL…

No fix yet
Fix from $1,950 2011-10-09
Com Camelcitydb2 HIGH 7.5
CVE-2010-4945

SQL injection vulnerability in the CamelcityDB (com_camelcitydb2) component 2.2 for Joomla! allows remote attackers to execute arbitrary SQL commands…

No fix yet
Fix from $1,950 2011-10-09
Com Weblinks HIGH 7.5
CVE-2010-4938

SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Ite…

No fix yet
Fix from $1,950 2011-10-09
Joomla\! MEDIUM 5.0
CVE-2011-3747

Joomla! 1.6.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …

No fix yet
Fix from $1,600 2011-09-23
Joomla\! MEDIUM 5.0
CVE-2011-2488

Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.

Fix: after 1.5.22
Fix from $1,600 2011-07-27
Joomla\! MEDIUM 5.0
CVE-2011-2889

templates/system/error.php in Joomla! before 1.5.23 might allow remote attackers to obtain sensitive information via unspecified vectors that trigger…

Fix: after 1.5.22
Fix from $1,600 2011-07-27
Joomla\! MEDIUM 5.0
CVE-2011-2890

The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obt…

Fix: after 1.5.23
Fix from $1,600 2011-07-27
Joomla\! MEDIUM 5.0
CVE-2011-2891

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals th…

No fix yet
Fix from $1,600 2011-07-27
Joomla\! HIGH 7.5
CVE-2010-4696

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via the (1) filter_ord…

Mitigation only
Fix from $1,950 2011-01-18
Joomla\! HIGH 7.5
CVE-2010-4166

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_ord…

No fix yet
Fix from $1,950 2011-01-18
Com Sef HIGH 7.5
CVE-2010-2681

PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2010-07-12
Com Weblinks HIGH 7.5
CVE-2010-2679

SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id …

No fix yet
Fix from $1,950 2010-07-08
Com Newsfeeds HIGH 7.5
CVE-2010-1739

SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2010-05-06
Com Casino MEDIUM 6.5
CVE-2010-0461

SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id…

No fix yet
Fix from $1,600 2010-01-28
Com Libros HIGH 7.5
CVE-2010-0373

SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id par…

No fix yet
Fix from $1,950 2010-01-21
Com Dhforum HIGH 7.5
CVE-2009-4583

SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id p…

No fix yet
Fix from $1,950 2010-01-06
Joomla\! MEDIUM 5.5
CVE-2009-3945

Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Autho…

Fix: after 1.5.14
Fix from $1,600 2009-11-16
Joomla\! MEDIUM 5.0
CVE-2009-3946

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct reques…

Fix: after 1.5.14
Fix from $1,600 2009-11-16
Com Content HIGH 7.5
CVE-2008-6923

SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via th…

No fix yet
Fix from $1,950 2009-08-10
Joomla\! HIGH 7.5
CVE-2008-6852

SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands v…

No fix yet
Fix from $1,950 2009-07-07
Com Casiino Blackjack HIGH 7.5
CVE-2009-2239

SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3) casino_videopoker (com_casin…

No fix yet
Fix from $1,950 2009-06-27
Com School HIGH 7.5
CVE-2009-2014

SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,950 2009-06-09
Com Gsticketsystem HIGH 7.5
CVE-2009-1736

SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbit…

No fix yet
Fix from $1,950 2009-05-20
Joomla\! HIGH 7.5
CVE-2009-1499

SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the art…

No fix yet
Fix from $1,950 2009-05-01