Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2020-37226
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL…
HIGH
CVSS 7.1
CVE-2020-37224
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL…
HIGH
CVSS 7.1
CVE-2020-37219
Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder…
HIGH
CVSS 8.7
CVE-2020-37218
Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries…
HIGH
CVSS 8.8
CVE-2021-47930
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execu…
HIGH
CVSS 8.8
CVE-2025-54301
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-54300
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-54475
A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.
HIGH
CVSS 8.7
CVE-2025-54474
A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-54297
A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.
HIGH
CVSS 7.0
CVE-2025-54296
A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
HIGH
CVSS 7.0
CVE-2025-50127
A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-49486
A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.
HIGH
CVSS 8.6
CVE-2025-49485
A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' param…
HIGH
CVSS 8.6
CVE-2025-49484
A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid'…
HIGH
CVSS 8.7
CVE-2025-49468
A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered.
HIGH
CVSS 8.6
CVE-2025-32465
A stored XSS vulnerability in RSTickets!
HIGH
CVSS 8.5
CVE-2025-22210
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL…
HIGH
CVSS 7.2
CVE-2025-22205
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
HIGH
CVSS 7.5
CVE-2024-5736
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla!
HIGH
CVSS 8.2