Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2014-6632
Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vecto…
HIGH
CVSS 7.5
CVE-2014-6631
Cross-site scripting (XSS) vulnerability in com_media in Joomla!
MEDIUM
CVSS 4.3
CVE-2014-4960
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla!
HIGH
CVSS 7.5
CVE-2013-5956
Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) component 3.4.0 for Joomla!
MEDIUM
CVSS 4.3
CVE-2013-5951
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web sc…
LOW
CVSS 2.6
CVE-2013-5955
Cross-site scripting (XSS) vulnerability in manage.php in the PBBooking (com_pbbooking) component 2.4 for Joomla!
MEDIUM
CVSS 4.3
CVE-2013-5953
Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5…
MEDIUM
CVSS 4.3
CVE-2013-5952
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla!
MEDIUM
CVSS 4.3
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.…
MEDIUM
CVSS 4.3
CVE-2013-3933
Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla!
MEDIUM
CVSS 4.3
CVE-2014-1837
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla!
MEDIUM
CVSS 4.3
CVE-2014-0793
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla!
MEDIUM
CVSS 4.3
CVE-2014-0794
SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla!
MEDIUM
CVSS 4.3
CVE-2013-7219
SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla!
HIGH
CVSS 7.5
CVE-2013-5583
Joomla! Cross-site Scripting vulnerability
MEDIUM
CVSS 4.3
CVE-2013-5576
administrator/components/com_media/helpers/media.php in the media manager in Joomla!
MEDIUM
CVSS 6.8
CVE-2013-3719
Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla!
MEDIUM
CVSS 4.3
CVE-2013-3534
Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla!
MEDIUM
CVSS 4.3
CVE-2013-3267
Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla!
MEDIUM
CVSS 4.3
CVE-2013-3242
plugins/system/remember/remember.php in Joomla!
MEDIUM
CVSS 5.5