Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2017-7984
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
MEDIUM
CVSS 6.1
CVE-2017-7983
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
MEDIUM
CVSS 5.3
CVE-2017-7628
The "Smart related articles" extension 1.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2017-7627
The "Smart related articles" extension 1.1 for Joomla!
MEDIUM
CVSS 5.3
CVE-2017-7626
The "Smart related articles" extension 1.1 for Joomla!
MEDIUM
CVSS 6.1
CVE-2017-5673
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS.
MEDIUM
CVSS 6.1
CVE-2016-9081
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via…
CRITICAL
CVSS 9.8
CVE-2016-10114
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla!
CRITICAL
CVSS 9.8
CVE-2016-9838
An issue was discovered in components/com_users/models/registration.php in Joomla!
HIGH
CVSS 7.5
CVE-2016-9837
An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla!
HIGH
CVSS 7.5
CVE-2016-9836
The file scanning mechanism of JFilterInput::isFileSafe() in Joomla!
CRITICAL
CVSS 9.8
CVE-2016-8870
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla!
HIGH
CVSS 8.1
CVE-2016-8869
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla!
CRITICAL
CVSS 9.8
CVE-2016-1000122
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
HIGH
CVSS 7.2
CVE-2016-1000121
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
MEDIUM
CVSS 4.8
CVE-2016-1000120
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
HIGH
CVSS 7.2
CVE-2016-1000119
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
HIGH
CVSS 7.2
CVE-2016-1000125
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CRITICAL
CVSS 9.8
CVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CRITICAL
CVSS 9.8
CVE-2016-1000114
XSS in huge IT gallery v1.1.5 for Joomla
MEDIUM
CVSS 6.1