Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2009-4573
Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-4550
SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4475
SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla!
HIGH
CVSS 7.5
CVE-2009-4431
PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4428
SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4255
Cross-site scripting (XSS) vulnerability in the You!Hostit!
MEDIUM
CVSS 4.3
CVE-2009-4233
Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-4232
The Kide Shoutbox (com_kide) component 0.4.6 for Joomla!
MEDIUM
CVSS 5.0
CVE-2009-4217
SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla!
HIGH
CVSS 7.5
CVE-2009-4202
Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4200
SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4199
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disable…
MEDIUM
CVSS 6.8
CVE-2009-4168
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and…
MEDIUM
CVSS 4.3
CVE-2009-4157
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-4104
SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4099
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla!
HIGH
CVSS 7.5
CVE-2009-4094
PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla!
HIGH
CVSS 7.5
CVE-2009-4059
SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla!
MEDIUM
CVSS 6.8
CVE-2009-4057
SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla!
HIGH
CVSS 7.5
CVE-2009-3972
SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla!
HIGH
CVSS 7.5