Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1619 résultats

CVE-2025-27754 A stored XSS vulnerability in RSBlog! RSBlog · 1 source · MEDIUM CVSS 6.5 CVE-2025-27753 A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. RSMediaGallery · 1 source · MEDIUM CVSS 6.5 CVE-2025-27445 A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. RSFirewall · 1 source · MEDIUM CVSS 5.4 CVE-2025-27444 A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. RSform!Pro · 1 source · MEDIUM CVSS 4.8 CVE-2025-25228 A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the produc… Virtuemart · 1 source · LOW CVSS 3.8 CVE-2025-25226 Multiples vulnérabilités dans Joomla! Joomla CMS · 1 source · UNKNOWN CVE-2025-25227 Joomla CMS Multi-Factor Authentication Bypass Joomla CMS · 3 sources · HIGH CVSS 7.5 CVE-2025-2714 A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. jux_real_estate · 1 source · MEDIUM CVSS 5.3 CVE-2025-25225 A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their… Hikashop · 1 source · MEDIUM CVSS 6.5 CVE-2025-22213 Vulnérabilité dans Joomla! Joomla CMS · 1 source · UNKNOWN CVE-2025-2127 A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. jux_real_estate · 1 source · MEDIUM CVSS 5.3 CVE-2025-2126 A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. jux_real_estate · 1 source · MEDIUM CVSS 5.3 CVE-2025-22212 A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute… Convert Forms · 1 source · LOW CVSS 2.7 CVE-2025-22211 A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary… JoomShopping · 1 source · LOW CVSS 3.4 CVE-2025-22210 A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL… Hikashop · 1 source · HIGH CVSS 7.2 CVE-2025-22207 Vulnérabilité dans Joomla! Joomla CMS · 1 source · UNKNOWN CVE-2025-22209 A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com… JS Jobs · 1 source · MEDIUM CVSS 4.7 CVE-2025-22208 A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com… JS Jobs · 1 source · MEDIUM CVSS 4.7 CVE-2025-22206 A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com… JS Jobs · 1 source · MEDIUM CVSS 4.7 CVE-2025-22205 Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x. Admiror Gallery · 1 source · HIGH CVSS 7.5