Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

222 résultats

CVE-2017-17875 The JEXTN FAQ Pro extension 4.0.0 for Joomla! jextn_faq_pro · 1 source · CRITICAL CVSS 9.8 CVE-2017-17872 The JEXTN Video Gallery extension 3.0.5 for Joomla! jextn_video_gallery · 1 source · CRITICAL CVSS 9.8 CVE-2017-17871 The "JEXTN Question And Answer" extension 3.1.0 for Joomla! jextn_question_and_answer · 1 source · CRITICAL CVSS 9.8 CVE-2017-17870 The JBuildozer extension 1.4.1 for Joomla! jbuildozer · 1 source · CRITICAL CVSS 9.8 CVE-2017-16634 In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2017-15966 The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! zh_yandexmap · 1 source · CRITICAL CVSS 9.8 CVE-2017-15965 The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! ns_download_shop · 1 source · CRITICAL CVSS 9.8 CVE-2017-15946 In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. tag_meta · 1 source · CRITICAL CVSS 9.8 CVE-2017-14596 In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2015-4073 Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! helpdesk_pro · 1 source · CRITICAL CVSS 9.8 CVE-2013-7429 The Googlemaps plugin before 3.1 for Joomla! googlemaps · 1 source · CRITICAL CVSS 9.8 CVE-2015-2798 SQL injection vulnerability in Joomla! contact_form_maker · 1 source · CRITICAL CVSS 9.8 CVE-2017-8917 SQL injection vulnerability in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2017-5215 The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! b2j_contact · 1 source · CRITICAL CVSS 9.8 CVE-2017-7628 The "Smart related articles" extension 1.1 for Joomla! smart_related_articles · 1 source · CRITICAL CVSS 9.8 CVE-2016-9081 Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via… Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2016-10114 SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! aweb_cart_watching_system_for_virtuemart · 1 source · CRITICAL CVSS 9.8 CVE-2016-9836 The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2016-8869 The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2016-1000125 Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla huge-it_catalog · 1 source · CRITICAL CVSS 9.8