Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1619 résultats

CVE-2011-4908 TinyBrowser plugin for Joomla! tinybrowser · 1 source · CRITICAL CVSS 9.8 CVE-2011-4906 Tiny browser in TinyMCE 3.0 editor in Joomla! tinybrowser · 1 source · CRITICAL CVSS 9.8 CVE-2014-8739 Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Cre… creative_contact_form · 1 source · CRITICAL CVSS 9.8 CVE-2011-1151 Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. Joomla CMS · 1 source · CRITICAL CVSS 9.1 CVE-2011-4912 Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. Joomla CMS · 1 source · MEDIUM CVSS 5.3 CVE-2011-4937 Joomla! 1.7.1 has core information disclosure due to inadequate error checking. Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2011-3629 Joomla! core 1.7.1 allows information disclosure due to weak encryption Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2020-5182 The J-BusinessDirectory extension before 5.2.9 for Joomla! j-businessdirectory · 1 source · MEDIUM CVSS 6.5 CVE-2020-8421 An issue was discovered in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 6.1 CVE-2020-8420 An issue was discovered in Joomla! Joomla CMS · 1 source · HIGH CVSS 8.8 CVE-2020-8419 An issue was discovered in Joomla! Joomla CMS · 1 source · HIGH CVSS 8.8 CVE-2011-3595 Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 5.4 CVE-2011-4907 Joomla! 1.5x through 1.5.12: Missing JEXEC Check Joomla CMS · 1 source · MEDIUM CVSS 5.3 CVE-2012-1563 Joomla! before 2.5.3 allows Admin Account Creation. Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2012-1562 Joomla! core before 2.5.3 allows unauthorized password change. Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2013-3932 SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! jomres · 1 source · HIGH CVSS 8.8 CVE-2013-3931 Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! jomres · 1 source · MEDIUM CVSS 5.4 CVE-2019-17527 dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! js_jobs · 1 source · CRITICAL CVSS 9.8 CVE-2019-19846 In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2019-19845 In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. Joomla CMS · 1 source · MEDIUM CVSS 5.3