Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1619 résultats

CVE-2020-13761 In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS. Joomla CMS · 1 source · MEDIUM CVSS 6.1 CVE-2020-13760 In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. Joomla CMS · 1 source · HIGH CVSS 8.8 CVE-2020-13424 The XCloner component before 3.5.4 for Joomla! xcloner · 1 source · MEDIUM CVSS 6.5 CVE-2020-11891 An issue was discovered in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 5.3 CVE-2020-11890 An issue was discovered in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 5.3 CVE-2020-11889 An issue was discovered in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 5.3 CVE-2020-10243 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2020-10242 An issue was discovered in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 6.1 CVE-2020-10241 An issue was discovered in Joomla! Joomla CMS · 1 source · HIGH CVSS 8.8 CVE-2020-10240 An issue was discovered in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 5.3 CVE-2020-10239 An issue was discovered in Joomla! Joomla CMS · 1 source · HIGH CVSS 8.8 CVE-2020-10238 An issue was discovered in Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2015-7342 JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field. jnews · 1 source · HIGH CVSS 7.2 CVE-2015-7341 JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. jnews · 1 source · HIGH CVSS 8.8 CVE-2015-7340 JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action. jevents · 1 source · HIGH CVSS 7.2 CVE-2015-7339 JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.p… jce · 1 source · HIGH CVSS 8.8 CVE-2015-7338 SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php. acymailing · 1 source · HIGH CVSS 7.2 CVE-2015-7344 HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption]. hikashop · 1 source · MEDIUM CVSS 4.8 CVE-2015-7343 JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter. jnews · 1 source · MEDIUM CVSS 4.8 CVE-2020-9364 An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. creative_contact_form · 1 source · MEDIUM CVSS 5.3