Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

368 résultats

CVE-2026-58149 User enumeration in Events Booking < 5.8.0 Extension Joomla — joomdonation.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-48943 K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. k2 · 1 source · MEDIUM CVSS 6.5 CVE-2019-25760 Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base… easy_shop · 1 source · MEDIUM CVSS 6.9 CVE-2018-25354 Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authent… Extension Joomla — Jomres · 1 source · MEDIUM CVSS 5.3 CVE-2018-25337 Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated user… Extension Joomla — Joomlaextensions · 1 source · MEDIUM CVSS 5.3 CVE-2018-25327 Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token valid… Extension Joomla — Joomsky · 1 source · MEDIUM CVSS 6.9 CVE-2023-54364 Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating… Extension Joomla (identification incertaine) · 1 source · MEDIUM CVSS 5.1 CVE-2023-54363 Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulatin… Extension Joomla — Solidres · 1 source · MEDIUM CVSS 5.1 CVE-2023-54362 Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulatin… Extension Joomla (identification incertaine) · 1 source · MEDIUM CVSS 5.1 CVE-2023-54361 Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating th… Extension Joomla — Thethinkery · 1 source · MEDIUM CVSS 5.1 CVE-2023-54360 Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_i… Extension Joomla — Jlexart · 1 source · MEDIUM CVSS 5.1 CVE-2026-21625 User provided uploads to the Easy Discuss component for Joomla aren't properly validated. easydiscuss · 1 source · MEDIUM CVSS 4.8 CVE-2025-55758 Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered. JDownloads · 1 source · MEDIUM CVSS 5.4 CVE-2025-55757 A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered. Virtuemart · 1 source · MEDIUM CVSS 6.1 CVE-2025-54295 A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered. DJ-Reviews · 1 source · MEDIUM CVSS 5.1 CVE-2025-50126 A stored XSS vulnerability in the RSBlog! RSBlog! · 1 source · MEDIUM CVSS 5.3 CVE-2025-50058 A stored XSS vulnerability in the RSDirectory! RSDirectory! · 1 source · MEDIUM CVSS 5.1 CVE-2025-50057 A DOS vulnerability in RSFiles! RSFiles! · 1 source · MEDIUM CVSS 6.9 CVE-2025-50056 A reflected XSS vulnerability in RSMail! RSMail! · 1 source · MEDIUM CVSS 5.1 CVE-2025-32466 A SQL injection vulnerability in RSMediaGallery! RSMediaGallery · 1 source · MEDIUM CVSS 6.7