Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2025-30085
Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered.
CRITICAL
CVSS 9.2
CVE-2025-22204
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
CRITICAL
CVSS 9.8
CVE-2024-40744
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
CRITICAL
CVSS 9.8
CVE-2024-11145
Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privi…
CRITICAL
CVSS 9.3
CVE-2023-49708
SQLi vulnerability in Starshop component for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-49707
SQLi vulnerability in S5 Register module for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-40630
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-40629
SQLi vulnerability in LMS Lite component for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-39970
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla.
CRITICAL
CVSS 9.8
CVE-2023-23753
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query.
CRITICAL
CVSS 9.8
CVE-2023-28731
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to un…
CRITICAL
CVSS 9.8
CVE-2016-15016
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2.
CRITICAL
CVSS 9.8
CVE-2010-10003
A vulnerability classified as critical was found in gesellix titlelink on Joomla.
CRITICAL
CVSS 9.8
CVE-2011-4908
TinyBrowser plugin for Joomla!
CRITICAL
CVSS 9.8
CVE-2011-4906
Tiny browser in TinyMCE 3.0 editor in Joomla!
CRITICAL
CVSS 9.8
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Cre…
CRITICAL
CVSS 9.8
CVE-2019-17527
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
CVSS 9.8
CVE-2019-17399
The Shack Forms Pro extension before 4.0.32 for Joomla!
CRITICAL
CVSS 9.8