Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2018-17378
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17377
SQL Injection exists in the Questions 1.4.3 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17375
SQL Injection exists in the Music Collection 3.0.3 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-14592
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-17254
The JCK Editor component 6.4.4 for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-15882
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2018-15881
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2018-15880
An issue was discovered in Joomla!
MEDIUM
CVSS 5.4
CVE-2017-18345
The Joomanager component through 2.0.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-12712
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2018-12711
An XSS issue was discovered in the language switcher module in Joomla!
MEDIUM
CVSS 6.1
CVE-2018-11690
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-12254
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla!
HIGH
CVSS 8.8
CVE-2018-6378
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
MEDIUM
CVSS 6.1
CVE-2018-11328
An issue was discovered in Joomla!
MEDIUM
CVSS 4.7
CVE-2018-11327
An issue was discovered in Joomla!
MEDIUM
CVSS 4.3
CVE-2018-11326
Joomla! XSS Vulnerability
MEDIUM
CVSS 4.8
CVE-2018-11325
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2018-11324
An issue was discovered in Joomla!
MEDIUM
CVSS 5.9