Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2023-23756
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-23755
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2023-23754
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2023-23753
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query.
CRITICAL
CVSS 9.8
CVE-2023-28733
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when acce…
MEDIUM
CVSS 6.1
CVE-2023-28732
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system…
HIGH
CVSS 7.5
CVE-2023-28731
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to un…
CRITICAL
CVSS 9.8
CVE-2023-23752
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2023-23750
An issue was discovered in Joomla!
MEDIUM
CVSS 6.3
CVE-2023-23751
An issue was discovered in Joomla!
MEDIUM
CVSS 4.3
CVE-2016-15016
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2.
CRITICAL
CVSS 9.8
CVE-2010-10003
A vulnerability classified as critical was found in gesellix titlelink on Joomla.
CRITICAL
CVSS 9.8
CVE-2022-27914
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2022-27913
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2022-27912
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2022-27911
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2022-27910
In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload f…
MEDIUM
CVSS 6.1
CVE-2022-27909
In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files
MEDIUM
CVSS 4.3
CVE-2022-23802
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions.
HIGH
CVSS 7.5
CVE-2022-23801
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1