Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2018-17380
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17379
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17378
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17377
SQL Injection exists in the Questions 1.4.3 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17375
SQL Injection exists in the Music Collection 3.0.3 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-14592
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17254
The JCK Editor component 6.4.4 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-18345
The Joomanager component through 2.0.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-11690
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-12254
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla!
HIGH
CVSS 8.8
CVE-2018-10063
The Convert Forms extension before 2.0.4 for Joomla!
HIGH
CVSS 7.8
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-9183
The Joom Sky JS Jobs extension before 1.2.1 for Joomla!
MEDIUM
CVSS 5.4
CVE-2018-9107
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla!
HIGH
CVSS 8.8
CVE-2018-9106
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla!
HIGH
CVSS 8.8
CVE-2018-7717
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-7482
The K2 component 2.8.0 for Joomla!
HIGH
CVSS 7.5
CVE-2018-7319
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7318
SQL Injection exists in the CheckList 1.1.1 component for Joomla!
CRITICAL
CVSS 9.8