Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2016-9081
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via…
CRITICAL
CVSS 9.8
CVE-2016-9838
An issue was discovered in components/com_users/models/registration.php in Joomla!
HIGH
CVSS 7.5
CVE-2016-9837
An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla!
HIGH
CVSS 7.5
CVE-2016-9836
The file scanning mechanism of JFilterInput::isFileSafe() in Joomla!
CRITICAL
CVSS 9.8
CVE-2016-8870
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla!
HIGH
CVSS 8.1
CVE-2016-8869
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla!
CRITICAL
CVSS 9.8
CVE-2015-8769
SQL injection vulnerability in Joomla!
HIGH
CVSS 7.3
CVE-2015-8565
Directory traversal vulnerability in Joomla!
HIGH
CVSS 7.5
CVE-2015-8564
Directory traversal vulnerability in Joomla!
HIGH
CVSS 7.5
CVE-2015-8563
Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla!
MEDIUM
CVSS 6.8
CVE-2015-7899
The com_content component in Joomla!
MEDIUM
CVSS 5.0
CVE-2015-7859
The com_contenthistory component in Joomla!
MEDIUM
CVSS 5.0
CVE-2015-7297
SQL injection vulnerability in Joomla!
HIGH
CVSS 7.5
CVE-2015-6939
Cross-site scripting (XSS) vulnerability in the login module in Joomla!
MEDIUM
CVSS 4.3
CVE-2015-5397
Cross-site request forgery (CSRF) vulnerability in Joomla!
MEDIUM
CVSS 6.8
CVE-2015-4654
SQL injection vulnerability in the EQ Event Calendar component for Joomla!
HIGH
CVSS 7.5
CVE-2014-7228
Akeeba Restore (restore.php), as used in Joomla!
HIGH
CVSS 7.5
CVE-2012-2413
Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla!
MEDIUM
CVSS 4.3
CVE-2014-7984
Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving GMail authe…
HIGH
CVSS 7.5
CVE-2014-7983
Cross-site scripting (XSS) vulnerability in com_contact in Joomla!
MEDIUM
CVSS 4.3