Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1220 résultats

CVE-2017-20262 Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal… ajax_quiz · 1 source · HIGH CVSS 8.8 CVE-2017-20261 Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj… bargain_product_vm3 · 1 source · HIGH CVSS 8.8 CVE-2017-20260 Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting… price_alert · 1 source · HIGH CVSS 8.8 CVE-2017-20259 Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious… osdownloads · 1 source · HIGH CVSS 8.8 CVE-2017-20258 Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries… responsive_portfolio · 1 source · HIGH CVSS 8.8 CVE-2017-20257 Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the… quiz_deluxe · 1 source · HIGH CVSS 8.8 CVE-2017-20256 Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma… survey_force_deluxe · 1 source · HIGH CVSS 8.8 CVE-2017-20255 Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malic… jb_visa · 1 source · HIGH CVSS 8.8 CVE-2017-20254 Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma… user_bench · 1 source · HIGH CVSS 8.8 CVE-2017-20253 Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting m… my_projects · 1 source · HIGH CVSS 8.8 CVE-2017-20252 Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname… nextgen_editor · 1 source · HIGH CVSS 8.8 CVE-2026-48907 A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code u… jce · 1 source · CRITICAL CVSS 10.0 CVE-2019-25740 Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield… com_jsjobs · 1 source · HIGH CVSS 7.1 CVE-2018-25433 Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injectin… com_jephotogallery · 1 source · HIGH CVSS 8.8 CVE-2018-25381 Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multipl… Extension Joomla — Extro · 1 source · HIGH CVSS 7.1 CVE-2018-25380 Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the fil… Extension Joomla — Extro · 1 source · HIGH CVSS 7.1 CVE-2018-25354 Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authent… Extension Joomla — Jomres · 1 source · MEDIUM CVSS 5.3 CVE-2018-25351 Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i… Extension Joomla — harmistechnology · 1 source · HIGH CVSS 8.8 CVE-2018-25348 Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL… Extension Joomla — harmistechnology · 1 source · HIGH CVSS 8.8 CVE-2018-25337 Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated user… Extension Joomla — Joomlaextensions · 1 source · MEDIUM CVSS 5.3