Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2011-1151
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
CRITICAL
CVSS 9.1
CVE-2011-4912
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
MEDIUM
CVSS 5.3
CVE-2011-4937
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
HIGH
CVSS 7.5
CVE-2011-3629
Joomla! core 1.7.1 allows information disclosure due to weak encryption
HIGH
CVSS 7.5
CVE-2020-8421
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2020-8420
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2020-8419
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2011-3595
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla!
MEDIUM
CVSS 5.4
CVE-2011-4907
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
MEDIUM
CVSS 5.3
CVE-2012-1563
Joomla! before 2.5.3 allows Admin Account Creation.
HIGH
CVSS 7.5
CVE-2012-1562
Joomla! core before 2.5.3 allows unauthorized password change.
HIGH
CVSS 7.5
CVE-2019-19846
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
CRITICAL
CVSS 9.8
CVE-2019-19845
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
MEDIUM
CVSS 5.3
CVE-2019-18674
An issue was discovered in Joomla!
MEDIUM
CVSS 5.3
CVE-2019-18650
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2019-16725
Joomla! XSS in Default Templates
MEDIUM
CVSS 6.1
CVE-2019-15028
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
MEDIUM
CVSS 5.3
CVE-2019-14654
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated…
HIGH
CVSS 8.8
CVE-2019-12766
An issue was discovered in Joomla!
MEDIUM
CVSS 6.1
CVE-2019-12765
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8