Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1220 résultats

CVE-2018-25330 Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code throug… Extension Joomla — Joomlaextensions · 1 source · HIGH CVSS 8.8 CVE-2018-25327 Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token valid… Extension Joomla — Joomsky · 1 source · MEDIUM CVSS 6.9 CVE-2020-37226 Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL… Extension Joomla (identification incertaine) · 1 source · HIGH CVSS 7.1 CVE-2020-37224 Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL… Extension Joomla (identification incertaine) · 1 source · HIGH CVSS 7.1 CVE-2020-37219 Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder… com_fabrik · 1 source · HIGH CVSS 8.7 CVE-2020-37218 Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries… com_hdwplayer · 1 source · HIGH CVSS 8.8 CVE-2021-47930 Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execu… com_baforms · 1 source · HIGH CVSS 8.8 CVE-2026-34424 Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that all… Extension Joomla (identification incertaine) · 1 source · CRITICAL CVSS 9.3 CVE-2023-54364 Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating… Extension Joomla (identification incertaine) · 1 source · MEDIUM CVSS 5.1 CVE-2023-54363 Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulatin… Extension Joomla — Solidres · 1 source · MEDIUM CVSS 5.1 CVE-2023-54362 Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulatin… Extension Joomla (identification incertaine) · 1 source · MEDIUM CVSS 5.1 CVE-2023-54361 Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating th… Extension Joomla — Thethinkery · 1 source · MEDIUM CVSS 5.1 CVE-2023-54360 Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_i… Extension Joomla — Jlexart · 1 source · MEDIUM CVSS 5.1 CVE-2026-21627 The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. com_ajax · 1 source · CRITICAL CVSS 9.5 CVE-2026-21625 User provided uploads to the Easy Discuss component for Joomla aren't properly validated. easydiscuss · 1 source · MEDIUM CVSS 4.8 CVE-2026-21624 Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla. easydiscuss · 1 source · CRITICAL CVSS 9.4 CVE-2026-21623 Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla. easydiscuss · 1 source · CRITICAL CVSS 9.4 CVE-2025-55758 Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered. JDownloads · 1 source · MEDIUM CVSS 5.4 CVE-2025-55757 A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered. Virtuemart · 1 source · MEDIUM CVSS 6.1 CVE-2025-40636 SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. mod_vvisit_counter · 1 source · CRITICAL CVSS 9.3