Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2020-13761
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
MEDIUM
CVSS 6.1
CVE-2020-13760
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
HIGH
CVSS 8.8
CVE-2020-13424
The XCloner component before 3.5.4 for Joomla!
MEDIUM
CVSS 6.5
CVE-2020-11891
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2020-11890
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2020-11889
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2020-10243
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2020-10242
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2020-10241
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2020-10240
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2020-10239
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2020-10238
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2015-7342
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.
HIGH
CVSS 7.2
CVE-2015-7341
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
HIGH
CVSS 8.8
CVE-2015-7340
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
HIGH
CVSS 7.2
CVE-2015-7339
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.p…
HIGH
CVSS 8.8
CVE-2015-7338
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
HIGH
CVSS 7.2
CVE-2015-7344
HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
MEDIUM
CVSS 4.8
CVE-2015-7343
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
MEDIUM
CVSS 4.8
CVE-2020-9364
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!.
MEDIUM
CVSS 5.3