Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2018-11324 An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could c… Joomla\! 3.8.8+ Fix from $1,6002018-05-22 HIGH 8.8 CVE-2018-8045EPSS 29% In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes li… Joomla\! after 3.8.5 Fix from $1,9502018-03-15 CRITICAL 9.8 CVE-2018-6376 In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall m… Joomla\! 3.8.4+ Fix from $2,3002018-01-30 MEDIUM 6.1 CVE-2018-6377EPSS 57% In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and check… Joomla\! 3.8.4+ Fix from $1,6002018-01-30 MEDIUM 6.1 CVE-2018-6379 In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability. Joomla\! 3.8.4+ Fix from $1,6002018-01-30 MEDIUM 6.1 CVE-2018-6380 In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. Joomla\! 3.8.4+ Fix from $1,6002018-01-30 CRITICAL 9.8 CVE-2017-16634 In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. Joomla\! after 3.8.1 Fix from $2,3002017-11-10 CRITICAL 9.8 CVE-2017-14596EPSS 7% In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. Joomla\! No fix yet Fix from $2,3002017-09-20 MEDIUM 6.1 CVE-2015-5608 Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1. Joomla\! Mitigation only Fix from $1,6002017-09-20 HIGH 8.8 CVE-2017-11364 The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control o… Joomla\! Mitigation only Fix from $1,9502017-08-02 MEDIUM 6.1 CVE-2017-11612 In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components. Joomla\! Mitigation only Fix from $1,6002017-07-26 HIGH 7.5 CVE-2017-9933 Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. Joomla\! Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-9934 Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability. Joomla\! Mitigation only Fix from $1,6002017-07-17 CRITICAL 9.8 CVE-2017-8917EPSS 100% SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. Joomla\! Patch available Fix from $2,3002017-05-17 MEDIUM 6.5 CVE-2017-7989 In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explic… Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 6.1 CVE-2017-7984 In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 6.1 CVE-2017-7985 In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components. Joomla\! after 3.6.5 Fix from $1,6002017-04-25 MEDIUM 6.1 CVE-2017-7986 In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components. Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 6.1 CVE-2017-7987 In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager co… Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 5.3 CVE-2017-7983 In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 5.3 CVE-2017-7988 In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 5.3 CVE-2017-8057 In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting. Joomla\! Patch available Fix from $1,6002017-04-25 CRITICAL 9.8 CVE-2016-9081 Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifica… Joomla\! Patch available Fix from $2,3002017-01-23 HIGH 7.5 CVE-2016-9837 An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 l… Joomla\! after 3.6.4 Fix from $1,9502016-12-16 HIGH 7.5 CVE-2016-9838EPSS 14% An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored… Joomla\! after 3.6.4 Fix from $1,9502016-12-16 CRITICAL 9.8 CVE-2016-9836 The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking… Joomla\! after 3.6.4 Fix from $2,3002016-12-05 HIGH 8.1 CVE-2016-8870EPSS 81% The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has… Joomla\! after 3.6.3 Fix from $1,9502016-11-04 CRITICAL 9.8 CVE-2016-8869EPSS 97% The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attacker… Joomla\! after 3.6.3 Fix from $2,3002016-11-04 HIGH 7.3 CVE-2015-8769 SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors. Joomla\! Mitigation only Fix from $1,9502016-01-12 HIGH 7.5 CVE-2015-8566EPSS 8% The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values. Session Mitigation only Fix from $1,9502015-12-16