Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2024-21727
XSS vulnerability in DP Calendar component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40659
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40658
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40657
A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40656
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40655
A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40628
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-40627
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-39974
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla.
MEDIUM
CVSS 5.3
CVE-2023-39973
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla.
MEDIUM
CVSS 4.3
CVE-2023-39972
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla.
MEDIUM
CVSS 4.3
CVE-2023-39971
Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS.
MEDIUM
CVSS 6.1
CVE-2023-38045
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-23756
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla.
MEDIUM
CVSS 6.1
CVE-2023-28733
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when acce…
MEDIUM
CVSS 6.1
CVE-2022-27910
In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload f…
MEDIUM
CVSS 6.1
CVE-2022-27909
In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files
MEDIUM
CVSS 4.3
CVE-2020-13424
The XCloner component before 3.5.4 for Joomla!
MEDIUM
CVSS 6.5
CVE-2015-7344
HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
MEDIUM
CVSS 4.8
CVE-2015-7343
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
MEDIUM
CVSS 4.8