Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2017-17870
The JBuildozer extension 1.4.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-16634
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
CRITICAL
CVSS 9.8
CVE-2017-16633
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
MEDIUM
CVSS 4.3
CVE-2017-15966
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-15946
In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php.
CRITICAL
CVSS 9.8
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla!
HIGH
CVSS 8.8
CVE-2015-7714
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla!
HIGH
CVSS 7.2
CVE-2014-9686
The Googlemaps plugin 3.2 and earlier for Joomla!
MEDIUM
CVSS 5.9
CVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
CRITICAL
CVSS 9.8
CVE-2017-14595
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
LOW
CVSS 3.7
CVE-2015-5608
Open redirect vulnerability in Joomla!
MEDIUM
CVSS 6.1
CVE-2015-4075
The Helpdesk Pro plugin before 1.4.0 for Joomla!
HIGH
CVSS 8.1
CVE-2015-4074
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla!
HIGH
CVSS 7.5
CVE-2015-4073
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla!
CRITICAL
CVSS 9.8
CVE-2015-4072
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla!
MEDIUM
CVSS 5.4
CVE-2013-7429
The Googlemaps plugin before 3.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-2550
Vulnerability in Easy Joomla Backup v3.2.4.
HIGH
CVSS 7.5
CVE-2013-7428
The Googlemaps plugin before 3.1 for Joomla!
HIGH
CVSS 7.5
CVE-2013-7433
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.
MEDIUM
CVSS 6.1