Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2025-22208
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22206
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22205
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
HIGH
CVSS 7.5
CVE-2025-22204
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
CRITICAL
CVSS 9.8
CVE-2024-40745
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
MEDIUM
CVSS 5.4
CVE-2024-40744
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
CRITICAL
CVSS 9.8
CVE-2024-11145
Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privi…
CRITICAL
CVSS 9.3
CVE-2024-40746
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web brows…
MEDIUM
CVSS 5.4
CVE-2024-27183
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
MEDIUM
CVSS 6.1
CVE-2024-5737
Script afGdStream.php in AdmirorFrames Joomla!
MEDIUM
CVSS 6.3
CVE-2024-5736
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla!
HIGH
CVSS 8.2
CVE-2024-5735
Full Path Disclosure vulnerability in AdmirorFrames Joomla!
MEDIUM
CVSS 6.3
CVE-2024-32788
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a th…
MEDIUM
CVSS 5.3
CVE-2024-24837
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joo…
MEDIUM
CVSS 4.3
CVE-2024-21728
An Open Redirect vulnerability was found in osTicky2 below 2.2.8.
MEDIUM
CVSS 6.1
CVE-2024-21727
XSS vulnerability in DP Calendar component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-49708
SQLi vulnerability in Starshop component for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-49707
SQLi vulnerability in S5 Register module for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-40659
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40658
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
MEDIUM
CVSS 6.1