Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2020-13762
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
Joomla\!
3.9.19+
MEDIUM 5.3
CVE-2020-11889
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of us…
Joomla\!
3.9.17+
MEDIUM 5.3
CVE-2020-11890
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
Joomla\!
3.9.17+
MEDIUM 5.3
CVE-2020-11891
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of use…
Joomla\!
3.9.17+
CRITICAL 9.8
CVE-2020-10243
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in…
Joomla\!
3.9.16+
HIGH 8.8
CVE-2020-10239
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
Joomla\!
3.9.16+
HIGH 8.8
CVE-2020-10241
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
Joomla\!
3.9.16+
HIGH 7.5
CVE-2020-10238
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack …
Joomla\!
3.9.16+
MEDIUM 6.1
CVE-2020-10242
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
Joomla\!
3.9.16+
MEDIUM 5.3
CVE-2020-10240
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames …
Joomla\!
3.9.16+
CRITICAL 9.1
CVE-2011-1151
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
Joomla\!
No fix yet
MEDIUM 5.3
CVE-2011-4912
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
Joomla\!
after 1.5.13
HIGH 7.5
CVE-2011-4937
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
Joomla\!
1.7.2+
HIGH 7.5
CVE-2011-3629
Joomla! core 1.7.1 allows information disclosure due to weak encryption
Joomla\!
1.7.2+
HIGH 8.8
CVE-2020-8420
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
Joomla\!
3.9.15+
MEDIUM 6.1
CVE-2020-8421
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
Joomla\!
3.9.14+
HIGH 8.8
CVE-2020-8419
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
Joomla\!
3.9.15+
MEDIUM 5.4
CVE-2011-3595
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author para…
Joomla\!
after 1.7.0
MEDIUM 5.3
CVE-2011-4907
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
Joomla\!
after 1.5.12
HIGH 7.5
CVE-2012-1562
Joomla! core before 2.5.3 allows unauthorized password change.
Joomla\!
2.5.3+
HIGH 7.5
CVE-2012-1563EPSS 9%
Joomla! before 2.5.3 allows Admin Account Creation.
Joomla\!
2.5.3+
CRITICAL 9.8
CVE-2019-19846
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
Joomla\!
after 3.9.14
MEDIUM 5.3
CVE-2019-19845
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
Joomla\!
3.9.14+
MEDIUM 5.3
CVE-2019-18674
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.
Joomla\!
3.9.13+
HIGH 8.8
CVE-2019-18650
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
Joomla\!
after 3.9.12
MEDIUM 6.1
CVE-2019-16725
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Joomla\!
3.9.12+
MEDIUM 5.3
CVE-2019-15028
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
Joomla\!
3.9.11+
HIGH 8.8
CVE-2019-14654
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an un…
Joomla\!
Mitigation only
CRITICAL 9.8
CVE-2019-12765EPSS 10%
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
Joomla\!
after 3.9.6
MEDIUM 6.5
CVE-2019-12764
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
Joomla\!
3.9.7+