Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
CVSS 9.8
CVE-2013-6879
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla!
MEDIUM
CVSS 5.3
CVE-2013-6878
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla!
MEDIUM
CVSS 6.1
CVE-2014-1214
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla!
HIGH
CVSS 8.8
CVE-2019-18674
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2019-18650
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2018-10727
Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla!
MEDIUM
CVSS 6.1
CVE-2019-17399
The Shack Forms Pro extension before 4.0.32 for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-16725
Joomla! XSS in Default Templates
MEDIUM
CVSS 6.1
CVE-2019-15120
The Kunena extension before 5.1.14 for Joomla!
MEDIUM
CVSS 5.4
CVE-2019-15028
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
MEDIUM
CVSS 5.3
CVE-2019-14654
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated…
HIGH
CVSS 8.8
CVE-2018-17386
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17381
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17374
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17399
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17398
SQL Injection exists in the AMGallery 1.2.3 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-12766
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2019-12765
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8