Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2025-27754
A stored XSS vulnerability in RSBlog!
MEDIUM
CVSS 6.5
CVE-2025-27753
A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered.
MEDIUM
CVSS 6.5
CVE-2025-27445
A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered.
MEDIUM
CVSS 5.4
CVE-2025-27444
A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered.
MEDIUM
CVSS 4.8
CVE-2025-2714
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0.
MEDIUM
CVSS 5.3
CVE-2025-25225
A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their…
MEDIUM
CVSS 6.5
CVE-2025-2127
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla.
MEDIUM
CVSS 5.3
CVE-2025-2126
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical.
MEDIUM
CVSS 5.3
CVE-2025-22209
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22208
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2025-22206
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL com…
MEDIUM
CVSS 4.7
CVE-2024-40745
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
MEDIUM
CVSS 5.4
CVE-2024-40746
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web brows…
MEDIUM
CVSS 5.4
CVE-2024-27183
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
MEDIUM
CVSS 6.1
CVE-2024-5737
Script afGdStream.php in AdmirorFrames Joomla!
MEDIUM
CVSS 6.3
CVE-2024-5735
Full Path Disclosure vulnerability in AdmirorFrames Joomla!
MEDIUM
CVSS 6.3
CVE-2024-32788
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a th…
MEDIUM
CVSS 5.3
CVE-2024-24837
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joo…
MEDIUM
CVSS 4.3
CVE-2024-21728
An Open Redirect vulnerability was found in osTicky2 below 2.2.8.
MEDIUM
CVSS 6.1
CVE-2024-21727
XSS vulnerability in DP Calendar component for Joomla.
MEDIUM
CVSS 6.1