Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

217 résultats

CVE-2025-30085 Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. RSform!Pro · 1 source · CRITICAL CVSS 9.2 CVE-2025-22204 Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. Sourcerer · 1 source · CRITICAL CVSS 9.8 CVE-2024-40744 Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. Convert Forms · 1 source · CRITICAL CVSS 9.8 CVE-2024-11145 Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privi… easy_folder_listing_pro · 1 source · CRITICAL CVSS 9.3 CVE-2023-49708 SQLi vulnerability in Starshop component for Joomla. Starshop · 1 source · CRITICAL CVSS 9.8 CVE-2023-49707 SQLi vulnerability in S5 Register module for Joomla. S5 Register · 1 source · CRITICAL CVSS 9.8 CVE-2023-40630 Unauthenticated LFI/SSRF in JCDashboards component for Joomla. JCDashboards · 1 source · CRITICAL CVSS 9.8 CVE-2023-40629 SQLi vulnerability in LMS Lite component for Joomla. LMS Lite · 1 source · CRITICAL CVSS 9.8 CVE-2023-39970 Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. AcyMailing · 1 source · CRITICAL CVSS 9.8 CVE-2023-23753 The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. visforms · 1 source · CRITICAL CVSS 9.8 CVE-2023-28731 AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to un… acymailing · 1 source · CRITICAL CVSS 9.8 CVE-2016-15016 A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. joomla_mod_einsatz_stats · 1 source · CRITICAL CVSS 9.8 CVE-2010-10003 A vulnerability classified as critical was found in gesellix titlelink on Joomla. titlelink · 1 source · CRITICAL CVSS 9.8 CVE-2022-23799 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2022-23797 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2022-23795 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2021-26040 An issue was discovered in Joomla! Joomla CMS · 2 sources · CRITICAL CVSS 9.1 CVE-2010-1435 Joomla! Core is prone to a security bypass vulnerability. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2010-1433 Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2021-23128 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.1