Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2015-7339
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.p…
HIGH
CVSS 8.8
CVE-2015-7338
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
HIGH
CVSS 7.2
CVE-2015-7344
HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
MEDIUM
CVSS 4.8
CVE-2015-7343
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
MEDIUM
CVSS 4.8
CVE-2020-9364
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!.
MEDIUM
CVSS 5.3
CVE-2011-4908
TinyBrowser plugin for Joomla!
CRITICAL
CVSS 9.8
CVE-2011-4906
Tiny browser in TinyMCE 3.0 editor in Joomla!
CRITICAL
CVSS 9.8
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Cre…
CRITICAL
CVSS 9.8
CVE-2020-5182
The J-BusinessDirectory extension before 5.2.9 for Joomla!
MEDIUM
CVSS 6.5
CVE-2013-3932
SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla!
HIGH
CVSS 8.8
CVE-2013-3931
Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla!
MEDIUM
CVSS 5.4
CVE-2019-17527
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
CVSS 9.8
CVE-2013-6879
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla!
MEDIUM
CVSS 5.3
CVE-2013-6878
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla!
MEDIUM
CVSS 6.1
CVE-2014-1214
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla!
HIGH
CVSS 8.8
CVE-2018-10727
Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla!
MEDIUM
CVSS 6.1
CVE-2019-17399
The Shack Forms Pro extension before 4.0.32 for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-15120
The Kunena extension before 5.1.14 for Joomla!
MEDIUM
CVSS 5.4