Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2009-1940
Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-1939
Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-1938
Cross-site scripting (XSS) vulnerability in Joomla!
MEDIUM
CVSS 4.3
CVE-2009-1499
SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla!
HIGH
CVSS 7.5
CVE-2009-1280
Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla!
MEDIUM
CVSS 6.8
CVE-2009-1279
Multiple cross-site scripting (XSS) vulnerabilities in Joomla!
LOW
CVSS 2.6
CVE-2008-6299
Multiple cross-site scripting (XSS) vulnerabilities in Joomla!
LOW
CVSS 3.5
CVE-2008-4122
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by int…
HIGH
CVSS 7.5
CVE-2008-5671
PHP remote file inclusion vulnerability in index.php in Joomla!
HIGH
CVSS 7.5
X-ab2f3f0c6f852382
Vulnérabilités dans Joomla!
UNKNOWN
CVE-2008-4107
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in pro…
MEDIUM
CVSS 5.1
CVE-2008-4105
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject…
HIGH
CVSS 7.5
CVE-2008-4104
Joomla! Open Redirect vulnerability
MEDIUM
CVSS 5.8
CVE-2008-4102
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra…
HIGH
CVSS 7.5
CVE-2008-3228
Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
HIGH
CVSS 7.5
CVE-2008-3227
Joomla! Open Redirect vulnerability
HIGH
CVSS 7.5
CVE-2008-3226
Joomla! allows attackers to access cached pages
MEDIUM
CVSS 5.0
CVE-2008-3225
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f…
HIGH
CVSS 10.0
CVE-2008-2990
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!
HIGH
CVSS 7.5
CVE-2008-2676
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla!
HIGH
CVSS 7.5