Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1220 résultats

CVE-2025-22208 A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com… JS Jobs · 1 source · MEDIUM CVSS 4.7 CVE-2025-22206 A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com… JS Jobs · 1 source · MEDIUM CVSS 4.7 CVE-2025-22205 Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x. Admiror Gallery · 1 source · HIGH CVSS 7.5 CVE-2025-22204 Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. Sourcerer · 1 source · CRITICAL CVSS 9.8 CVE-2024-40745 Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8. Convert Forms · 1 source · MEDIUM CVSS 5.4 CVE-2024-40744 Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. Convert Forms · 1 source · CRITICAL CVSS 9.8 CVE-2024-11145 Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privi… easy_folder_listing_pro · 1 source · CRITICAL CVSS 9.3 CVE-2024-40746 A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web brows… HikaShop · 1 source · MEDIUM CVSS 5.4 CVE-2024-27183 XSS vulnerability in DJ-HelpfulArticles component for Joomla. DJ-HelpfulArticles · 1 source · MEDIUM CVSS 6.1 CVE-2024-5737 Script afGdStream.php in AdmirorFrames Joomla! admirorframes · 1 source · MEDIUM CVSS 6.3 CVE-2024-5736 Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! admirorframes · 1 source · HIGH CVSS 8.2 CVE-2024-5735 Full Path Disclosure vulnerability in AdmirorFrames Joomla! admirorframes · 1 source · MEDIUM CVSS 6.3 CVE-2024-32788 Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a th… Extension Joomla (identification incertaine) · 1 source · MEDIUM CVSS 5.3 CVE-2024-24837 Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joo… Extension Joomla (identification incertaine) · 1 source · MEDIUM CVSS 4.3 CVE-2024-21728 An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky · 1 source · MEDIUM CVSS 6.1 CVE-2024-21727 XSS vulnerability in DP Calendar component for Joomla. DP Calendar · 1 source · MEDIUM CVSS 6.1 CVE-2023-49708 SQLi vulnerability in Starshop component for Joomla. Starshop · 1 source · CRITICAL CVSS 9.8 CVE-2023-49707 SQLi vulnerability in S5 Register module for Joomla. S5 Register · 1 source · CRITICAL CVSS 9.8 CVE-2023-40659 A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla. Easy Quick Contact · 1 source · MEDIUM CVSS 6.1 CVE-2023-40658 A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. Clicky Analytics Dashboard · 1 source · MEDIUM CVSS 6.1