Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2018-17857
An issue was discovered in Joomla!
MEDIUM
CVSS 4.3
CVE-2018-15880
An issue was discovered in Joomla!
MEDIUM
CVSS 5.4
CVE-2018-12711
An XSS issue was discovered in the language switcher module in Joomla!
MEDIUM
CVSS 6.1
CVE-2018-11690
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-6378
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
MEDIUM
CVSS 6.1
CVE-2018-11328
An issue was discovered in Joomla!
MEDIUM
CVSS 4.7
CVE-2018-11327
An issue was discovered in Joomla!
MEDIUM
CVSS 4.3
CVE-2018-11326
Joomla! XSS Vulnerability
MEDIUM
CVSS 4.8
CVE-2018-11324
An issue was discovered in Joomla!
MEDIUM
CVSS 5.9
CVE-2018-11321
An issue was discovered in com_fields in Joomla!
MEDIUM
CVSS 6.5
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-9183
The Joom Sky JS Jobs extension before 1.2.1 for Joomla!
MEDIUM
CVSS 5.4
CVE-2018-7717
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla!
MEDIUM
CVSS 6.1
CVE-2015-3619
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla!
MEDIUM
CVSS 5.4
CVE-2018-6380
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
MEDIUM
CVSS 6.1
CVE-2018-6379
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
MEDIUM
CVSS 6.1
CVE-2018-6377
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
MEDIUM
CVSS 6.1
CVE-2018-5263
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla!
MEDIUM
CVSS 5.4
CVE-2015-7324
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla!
MEDIUM
CVSS 6.1
CVE-2017-16633
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
MEDIUM
CVSS 4.3