Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

750 résultats

CVE-2018-25351 Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by i… Extension Joomla — harmistechnology · 1 source · HIGH CVSS 8.8 CVE-2018-25348 Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL… Extension Joomla — harmistechnology · 1 source · HIGH CVSS 8.8 CVE-2018-25330 Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code throug… Extension Joomla — Joomlaextensions · 1 source · HIGH CVSS 8.8 CVE-2020-37226 Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL… Extension Joomla (identification incertaine) · 1 source · HIGH CVSS 7.1 CVE-2020-37224 Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL… Extension Joomla (identification incertaine) · 1 source · HIGH CVSS 7.1 CVE-2020-37219 Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder… com_fabrik · 1 source · HIGH CVSS 8.7 CVE-2020-37218 Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries… com_hdwplayer · 1 source · HIGH CVSS 8.8 CVE-2021-47930 Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execu… com_baforms · 1 source · HIGH CVSS 8.8 CVE-2025-54301 A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. Quantum Mamanger · 1 source · HIGH CVSS 8.5 CVE-2025-54300 A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. Quantum Mamanger · 1 source · HIGH CVSS 8.5 CVE-2025-54475 A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands. JS Jobs · 1 source · HIGH CVSS 8.7 CVE-2025-54474 A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. DJ-Classifieds · 1 source · HIGH CVSS 8.5 CVE-2025-54297 A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered. CComment · 1 source · HIGH CVSS 7.0 CVE-2025-54296 A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. ProFiles · 1 source · HIGH CVSS 7.0 CVE-2025-50127 A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. DJ-Flyer · 1 source · HIGH CVSS 8.5 CVE-2025-49486 A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items. Balbooa Gallery · 1 source · HIGH CVSS 8.6 CVE-2025-49485 A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' param… Balbooa Forms · 1 source · HIGH CVSS 8.6 CVE-2025-49484 A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid'… JS Jobs · 1 source · HIGH CVSS 8.7 CVE-2025-49468 A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. No Boss Calendar · 1 source · HIGH CVSS 8.6 CVE-2025-32465 A stored XSS vulnerability in RSTickets! RSTickets! · 1 source · HIGH CVSS 8.5