Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2021-23128 An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an po… Joomla\! 3.9.25+ Fix from $2,3002021-03-04 HIGH 7.5 CVE-2021-23131 An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager. Joomla\! 3.9.25+ Fix from $1,9502021-03-04 HIGH 7.5 CVE-2021-23132EPSS 7% An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads Joomla\! 3.9.25+ Fix from $1,9502021-03-04 MEDIUM 6.1 CVE-2021-23129 An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 6.1 CVE-2021-23130 An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 5.5 CVE-2021-26028 An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 5.3 CVE-2021-23126 An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 5.3 CVE-2021-26027 An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 5.3 CVE-2021-26029 An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 6.1 CVE-2021-23124EPSS 81% An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks. Joomla\! after 3.9.23 Fix from $1,6002021-01-12 MEDIUM 6.1 CVE-2021-23125 An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XS… Joomla\! after 3.9.23 Fix from $1,6002021-01-12 MEDIUM 5.3 CVE-2021-23123 An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublishe… Joomla\! after 3.9.23 Fix from $1,6002021-01-12 HIGH 7.5 CVE-2020-35616EPSS 6% An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. Joomla\! after 3.9.22 Fix from $1,9502020-12-28 CRITICAL 9.8 CVE-2020-35613EPSS 29% An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backen… Joomla\! after 3.9.22 Fix from $2,3002020-12-28 HIGH 7.5 CVE-2020-35610 An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the correspondi… Joomla\! after 3.9.22 Fix from $1,9502020-12-28 HIGH 7.5 CVE-2020-35611 An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the … Joomla\! after 3.9.22 Fix from $1,9502020-12-28 HIGH 7.5 CVE-2020-35612 An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversa… Joomla\! after 3.9.22 Fix from $1,9502020-12-28 MEDIUM 6.3 CVE-2020-35615 An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability. Joomla\! after 3.9.22 Fix from $1,6002020-12-28 MEDIUM 5.3 CVE-2020-35614 An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend l… Joomla\! after 3.9.22 Fix from $1,6002020-12-28 MEDIUM 6.1 CVE-2020-24599 An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. Joomla\! 3.9.21+ Fix from $1,6002020-08-26 MEDIUM 6.1 CVE-2020-24598 An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. Joomla\! 3.9.21+ Fix from $1,6002020-08-26 MEDIUM 6.3 CVE-2020-15695 An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. Joomla\! after 3.9.19 Fix from $1,6002020-07-15 MEDIUM 6.3 CVE-2020-15700 An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. Joomla\! after 3.9.19 Fix from $1,6002020-07-15 MEDIUM 6.1 CVE-2020-15696 An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. Joomla\! after 3.9.19 Fix from $1,6002020-07-15 MEDIUM 5.3 CVE-2020-15698 An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials Joomla\! after 3.9.19 Fix from $1,6002020-07-15 MEDIUM 5.3 CVE-2020-15699 An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. Joomla\! after 3.9.19 Fix from $1,6002020-07-15 HIGH 8.8 CVE-2020-13760 In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. Joomla\! 3.9.19+ Fix from $1,9502020-06-02 HIGH 7.5 CVE-2020-13763 In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users. Joomla\! 3.9.19+ Fix from $1,9502020-06-02 MEDIUM 6.1 CVE-2020-13761 In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows… Joomla\! 3.9.19+ Fix from $1,6002020-06-02 MEDIUM 6.1 CVE-2020-13762 In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. Joomla\! 3.9.19+ Fix from $1,6002020-06-02