Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

368 résultats

CVE-2024-21727 XSS vulnerability in DP Calendar component for Joomla. DP Calendar · 1 source · MEDIUM CVSS 6.1 CVE-2023-40659 A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla. Easy Quick Contact · 1 source · MEDIUM CVSS 6.1 CVE-2023-40658 A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. Clicky Analytics Dashboard · 1 source · MEDIUM CVSS 6.1 CVE-2023-40657 A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla. Joomdoc · 1 source · MEDIUM CVSS 6.1 CVE-2023-40656 A reflected XSS vulnerability was discovered in the Quickform component for Joomla. Quickform · 1 source · MEDIUM CVSS 6.1 CVE-2023-40655 A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla. Proforms Basic · 1 source · MEDIUM CVSS 6.1 CVE-2023-40628 A reflected XSS vulnerability was discovered in the Extplorer component for Joomla. Extplorer · 1 source · MEDIUM CVSS 6.1 CVE-2023-40627 A reflected XSS vulnerability was discovered in the LivingWord component for Joomla. LivingWord · 1 source · MEDIUM CVSS 6.1 CVE-2023-39974 Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. AcyMailing Enterprise · 1 source · MEDIUM CVSS 5.3 CVE-2023-39973 Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. AcyMailing Enterprise · 1 source · MEDIUM CVSS 4.3 CVE-2023-39972 Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. AcyMailing Enterprise · 1 source · MEDIUM CVSS 4.3 CVE-2023-39971 Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. AcyMailing Enterprise · 1 source · MEDIUM CVSS 6.1 CVE-2023-38045 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. Admiror Gallery · 1 source · MEDIUM CVSS 6.1 CVE-2023-23756 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. oneVote · 1 source · MEDIUM CVSS 6.1 CVE-2023-28733 AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when acce… acymailing · 1 source · MEDIUM CVSS 6.1 CVE-2022-27910 In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload f… docman · 1 source · MEDIUM CVSS 6.1 CVE-2022-27909 In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files jdownloads · 1 source · MEDIUM CVSS 4.3 CVE-2020-13424 The XCloner component before 3.5.4 for Joomla! xcloner · 1 source · MEDIUM CVSS 6.5 CVE-2015-7344 HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption]. hikashop · 1 source · MEDIUM CVSS 4.8 CVE-2015-7343 JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter. jnews · 1 source · MEDIUM CVSS 4.8