Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1619 résultats

CVE-2018-6578 SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! je_paypervideo · 1 source · CRITICAL CVSS 9.8 CVE-2018-6577 SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! membership · 1 source · CRITICAL CVSS 9.8 CVE-2018-6575 SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! classified · 1 source · CRITICAL CVSS 9.8 CVE-2018-6380 In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. Joomla CMS · 1 source · MEDIUM CVSS 6.1 CVE-2018-6379 In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability. Joomla CMS · 1 source · MEDIUM CVSS 6.1 CVE-2018-6377 In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox Joomla CMS · 1 source · MEDIUM CVSS 6.1 CVE-2018-6376 In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2018-6398 SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! event_calendar · 1 source · CRITICAL CVSS 9.8 CVE-2018-6397 Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! picture_calendar · 1 source · HIGH CVSS 7.5 CVE-2018-6395 SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! visual_calendar · 1 source · CRITICAL CVSS 9.8 CVE-2018-6008 Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! jtag_members_directory · 1 source · HIGH CVSS 7.5 CVE-2018-6007 CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! js_support_ticket · 1 source · HIGH CVSS 8.8 CVE-2018-5985 SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! livecrm_saas_cloud · 1 source · CRITICAL CVSS 9.8 CVE-2018-5984 SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! tumder · 1 source · CRITICAL CVSS 9.8 CVE-2018-5696 The iJoomla com_adagency plugin 6.0.9 for Joomla! ad_agency · 1 source · CRITICAL CVSS 9.8 CVE-2018-5263 The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! easydiscuss · 1 source · MEDIUM CVSS 5.4 CVE-2015-7324 Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! komento · 1 source · MEDIUM CVSS 6.1 CVE-2017-17875 The JEXTN FAQ Pro extension 4.0.0 for Joomla! jextn_faq_pro · 1 source · CRITICAL CVSS 9.8 CVE-2017-17872 The JEXTN Video Gallery extension 3.0.5 for Joomla! jextn_video_gallery · 1 source · CRITICAL CVSS 9.8 CVE-2017-17871 The "JEXTN Question And Answer" extension 3.1.0 for Joomla! jextn_question_and_answer · 1 source · CRITICAL CVSS 9.8