Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2025-26854
A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.
CRITICAL
CVSS 9.8
CVE-2025-49468
A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered.
HIGH
CVSS 8.6
CVE-2025-49467
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered.
CRITICAL
CVSS 9.3
CVE-2025-32466
A SQL injection vulnerability in RSMediaGallery!
MEDIUM
CVSS 6.7
CVE-2025-32465
A stored XSS vulnerability in RSTickets!
HIGH
CVSS 8.5
CVE-2025-30085
Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered.
CRITICAL
CVSS 9.2
CVE-2025-30084
A stored XSS vulnerability in RSMail!
MEDIUM
CVSS 6.1
CVE-2025-27754
A stored XSS vulnerability in RSBlog!
MEDIUM
CVSS 6.5
CVE-2025-27753
A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered.
MEDIUM
CVSS 6.5
CVE-2025-27445
A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered.
MEDIUM
CVSS 5.4
CVE-2025-27444
A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered.
MEDIUM
CVSS 4.8
CVE-2025-25228
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the produc…
LOW
CVSS 3.8
CVE-2025-2714
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0.
MEDIUM
CVSS 5.3
CVE-2025-25225
A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their…
MEDIUM
CVSS 6.5
CVE-2025-2127
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla.
MEDIUM
CVSS 5.3
CVE-2025-2126
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical.
MEDIUM
CVSS 5.3
CVE-2025-22212
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute…
LOW
CVSS 2.7
CVE-2025-22211
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary…
LOW
CVSS 3.4
CVE-2025-22210
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL…
HIGH
CVSS 7.2
CVE-2025-22209
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7