Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2025-27754
A stored XSS vulnerability in RSBlog!
MEDIUM
CVSS 6.5
CVE-2025-27753
A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered.
MEDIUM
CVSS 6.5
CVE-2025-27445
A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered.
MEDIUM
CVSS 5.4
CVE-2025-27444
A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered.
MEDIUM
CVSS 4.8
CVE-2025-25228
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the produc…
LOW
CVSS 3.8
CVE-2025-25226
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2025-25227
Joomla CMS Multi-Factor Authentication Bypass
HIGH
CVSS 7.5
CVE-2025-2714
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0.
MEDIUM
CVSS 5.3
CVE-2025-25225
A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their…
MEDIUM
CVSS 6.5
CVE-2025-22213
Vulnérabilité dans Joomla!
UNKNOWN
CVE-2025-2127
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla.
MEDIUM
CVSS 5.3
CVE-2025-2126
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical.
MEDIUM
CVSS 5.3
CVE-2025-22212
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute…
LOW
CVSS 2.7
CVE-2025-22211
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary…
LOW
CVSS 3.4
CVE-2025-22210
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL…
HIGH
CVSS 7.2
CVE-2025-22207
Vulnérabilité dans Joomla!
UNKNOWN
CVE-2025-22209
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22208
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22206
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22205
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
HIGH
CVSS 7.5