Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2017-17875
The JEXTN FAQ Pro extension 4.0.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-17872
The JEXTN Video Gallery extension 3.0.5 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-17871
The "JEXTN Question And Answer" extension 3.1.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-17870
The JBuildozer extension 1.4.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-16634
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
CRITICAL
CVSS 9.8
CVE-2017-15966
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-15946
In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php.
CRITICAL
CVSS 9.8
CVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
CRITICAL
CVSS 9.8
CVE-2015-4073
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2013-7429
The Googlemaps plugin before 3.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2015-2798
SQL injection vulnerability in Joomla!
CRITICAL
CVSS 9.8
CVE-2017-8917
SQL injection vulnerability in Joomla!
CRITICAL
CVSS 9.8
CVE-2017-5215
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-7628
The "Smart related articles" extension 1.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2016-9081
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via…
CRITICAL
CVSS 9.8
CVE-2016-10114
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2016-9836
The file scanning mechanism of JFilterInput::isFileSafe() in Joomla!
CRITICAL
CVSS 9.8
CVE-2016-8869
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla!
CRITICAL
CVSS 9.8
CVE-2016-1000125
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CRITICAL
CVSS 9.8