Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

194 résultats

CVE-2025-30085 Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. RSform!Pro · 1 source · CRITICAL CVSS 9.2 CVE-2025-22204 Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. Sourcerer · 1 source · CRITICAL CVSS 9.8 CVE-2024-40744 Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. Convert Forms · 1 source · CRITICAL CVSS 9.8 CVE-2024-11145 Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privi… easy_folder_listing_pro · 1 source · CRITICAL CVSS 9.3 CVE-2023-49708 SQLi vulnerability in Starshop component for Joomla. Starshop · 1 source · CRITICAL CVSS 9.8 CVE-2023-49707 SQLi vulnerability in S5 Register module for Joomla. S5 Register · 1 source · CRITICAL CVSS 9.8 CVE-2023-40630 Unauthenticated LFI/SSRF in JCDashboards component for Joomla. JCDashboards · 1 source · CRITICAL CVSS 9.8 CVE-2023-40629 SQLi vulnerability in LMS Lite component for Joomla. LMS Lite · 1 source · CRITICAL CVSS 9.8 CVE-2023-39970 Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. AcyMailing · 1 source · CRITICAL CVSS 9.8 CVE-2023-23753 The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. visforms · 1 source · CRITICAL CVSS 9.8 CVE-2023-28731 AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to un… acymailing · 1 source · CRITICAL CVSS 9.8 CVE-2016-15016 A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. joomla_mod_einsatz_stats · 1 source · CRITICAL CVSS 9.8 CVE-2010-10003 A vulnerability classified as critical was found in gesellix titlelink on Joomla. titlelink · 1 source · CRITICAL CVSS 9.8 CVE-2011-4908 TinyBrowser plugin for Joomla! tinybrowser · 1 source · CRITICAL CVSS 9.8 CVE-2011-4906 Tiny browser in TinyMCE 3.0 editor in Joomla! tinybrowser · 1 source · CRITICAL CVSS 9.8 CVE-2014-8739 Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Cre… creative_contact_form · 1 source · CRITICAL CVSS 9.8 CVE-2019-17527 dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! js_jobs · 1 source · CRITICAL CVSS 9.8 CVE-2019-19634 class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! k2 · 1 source · CRITICAL CVSS 9.8 CVE-2019-19576 class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! k2 · 1 source · CRITICAL CVSS 9.8 CVE-2019-17399 The Shack Forms Pro extension before 4.0.32 for Joomla! shack_forms_pro · 1 source · CRITICAL CVSS 9.8