Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1220 résultats

CVE-2026-48943 K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. k2 · 1 source · MEDIUM CVSS 6.5 CVE-2026-48940 A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 store… k2 · 1 source · LOW CVSS 3.4 CVE-2026-48939 A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code uplo… icagenda · 1 source · CRITICAL CVSS 10.0 CVE-2026-48908 A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP c… sp_page_builder · 1 source · CRITICAL CVSS 10.0 CVE-2023-54357 Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploit… book_it! · 1 source · HIGH CVSS 8.7 CVE-2019-25762 Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by e… joomproject · 1 source · HIGH CVSS 8.7 CVE-2019-25761 Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malic… joomcrm · 1 source · HIGH CVSS 7.1 CVE-2019-25760 Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base… easy_shop · 1 source · MEDIUM CVSS 6.9 CVE-2019-25759 Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicio… vbizz · 1 source · HIGH CVSS 7.1 CVE-2019-25758 Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submittin… vbizz · 1 source · HIGH CVSS 8.7 CVE-2019-25757 Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code… vwishlist · 1 source · HIGH CVSS 7.1 CVE-2019-25756 Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma… vaccount · 1 source · HIGH CVSS 8.8 CVE-2019-25755 Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal… vreview · 1 source · HIGH CVSS 8.8 CVE-2019-25754 Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting… vrestaurant · 1 source · HIGH CVSS 8.8 CVE-2019-25753 Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici… vmap · 1 source · HIGH CVSS 8.8 CVE-2019-25752 Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i… j-businessdirectory · 1 source · HIGH CVSS 8.8 CVE-2019-25751 Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i… classifiedsmanager · 1 source · HIGH CVSS 8.8 CVE-2019-25750 Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie… multiplehotelreservation · 1 source · HIGH CVSS 8.8 CVE-2019-25749 Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious… j-cruiseportal · 1 source · HIGH CVSS 7.1 CVE-2019-25748 Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mali… jhotelreservation · 1 source · HIGH CVSS 8.8