Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2018-11323
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2018-11322
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2018-11321
An issue was discovered in com_fields in Joomla!
MEDIUM
CVSS 6.5
CVE-2018-10063
The Convert Forms extension before 2.0.4 for Joomla!
HIGH
CVSS 7.8
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-9183
The Joom Sky JS Jobs extension before 1.2.1 for Joomla!
MEDIUM
CVSS 5.4
CVE-2018-9107
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla!
HIGH
CVSS 8.8
CVE-2018-9106
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla!
HIGH
CVSS 8.8
CVE-2018-8045
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
HIGH
CVSS 8.8
CVE-2018-7717
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla!
MEDIUM
CVSS 6.1
CVE-2018-7482
The K2 component 2.8.0 for Joomla!
HIGH
CVSS 7.5
CVE-2018-7319
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7318
SQL Injection exists in the CheckList 1.1.1 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7317
Backup Download exists in the Proclaim 9.1.1 component for Joomla!
HIGH
CVSS 7.5
CVE-2018-7316
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7315
SQL Injection exists in the Ek Rishta 2.9 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7314
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7312
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-7313
SQL Injection exists in the CW Tags 2.0.6 component for Joomla!
CRITICAL
CVSS 9.8
CVE-2018-6024
SQL Injection exists in the Project Log 1.5.3 component for Joomla!
CRITICAL
CVSS 9.8