Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2018-10063
The Convert Forms extension before 2.0.4 for Joomla!
HIGH
CVSS 7.8
CVE-2018-9107
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla!
HIGH
CVSS 8.8
CVE-2018-9106
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla!
HIGH
CVSS 8.8
CVE-2018-8045
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
HIGH
CVSS 8.8
CVE-2018-7482
The K2 component 2.8.0 for Joomla!
HIGH
CVSS 7.5
CVE-2018-7317
Backup Download exists in the Proclaim 9.1.1 component for Joomla!
HIGH
CVSS 7.5
CVE-2018-6610
Information Leakage exists in the jLike 1.0 component for Joomla!
HIGH
CVSS 7.5
CVE-2018-6397
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla!
HIGH
CVSS 7.5
CVE-2018-6008
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla!
HIGH
CVSS 7.5
CVE-2018-6007
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla!
HIGH
CVSS 8.8
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla!
HIGH
CVSS 8.8
CVE-2015-7714
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla!
HIGH
CVSS 7.2
CVE-2015-4075
The Helpdesk Pro plugin before 1.4.0 for Joomla!
HIGH
CVSS 8.1
CVE-2015-4074
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla!
HIGH
CVSS 7.5
CVE-2017-2550
Vulnerability in Easy Joomla Backup v3.2.4.
HIGH
CVSS 7.5
CVE-2013-7428
The Googlemaps plugin before 3.1 for Joomla!
HIGH
CVSS 7.5
CVE-2013-7432
The Googlemaps plugin before 3.1 for Joomla!
HIGH
CVSS 7.5
CVE-2017-11364
The CMS installer in Joomla!
HIGH
CVSS 8.8
CVE-2017-9933
Improper cache invalidation in Joomla!
HIGH
CVSS 7.5
CVE-2016-10379
The VirtueMart com_virtuemart component 3.0.14 for Joomla!
HIGH
CVSS 7.2