Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

642 résultats

CVE-2026-57833 Unauthenticated stored XSS in 4Analytics < 5.0.2 Extension Joomla — weeblr.com · 1 source · HIGH CVSS 8.6 CVE-2026-57832 Unauthenticated blind SQL injection in EDocman < 3.9 Extension Joomla — joomdonation.com · 1 source · HIGH CVSS 8.7 CVE-2026-57831 Unauthenticated blind SQL injection in DP Calendar 8.18.0 Extension Joomla — digital-peak.com · 1 source · HIGH CVSS 8.7 CVE-2026-57830 Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 helix_ultimate · 1 source · HIGH CVSS 8.8 CVE-2026-57829 Unauthenticated stored XSS in Helix Ultimate < 2.2.7 helix_ultimate · 1 source · HIGH CVSS 8.7 CVE-2026-49049 The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and upda… helix3 · 1 source · HIGH CVSS 7.5 CVE-2026-49048 The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter in… joomcck · 1 source · HIGH CVSS 8.7 CVE-2023-54357 Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploit… book_it! · 1 source · HIGH CVSS 8.7 CVE-2019-25762 Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by e… joomproject · 1 source · HIGH CVSS 8.7 CVE-2019-25761 Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malic… joomcrm · 1 source · HIGH CVSS 7.1 CVE-2019-25759 Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicio… vbizz · 1 source · HIGH CVSS 7.1 CVE-2019-25758 Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submittin… vbizz · 1 source · HIGH CVSS 8.7 CVE-2019-25757 Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code… vwishlist · 1 source · HIGH CVSS 7.1 CVE-2019-25756 Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma… vaccount · 1 source · HIGH CVSS 8.8 CVE-2019-25755 Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal… vreview · 1 source · HIGH CVSS 8.8 CVE-2019-25754 Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting… vrestaurant · 1 source · HIGH CVSS 8.8 CVE-2019-25753 Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici… vmap · 1 source · HIGH CVSS 8.8 CVE-2019-25752 Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i… j-businessdirectory · 1 source · HIGH CVSS 8.8 CVE-2019-25751 Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i… classifiedsmanager · 1 source · HIGH CVSS 8.8 CVE-2019-25750 Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie… multiplehotelreservation · 1 source · HIGH CVSS 8.8