Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

644 résultats

CVE-2025-22205 Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x. Admiror Gallery · 1 source · HIGH CVSS 7.5 CVE-2024-5736 Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! admirorframes · 1 source · HIGH CVSS 8.2 CVE-2023-28732 Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system… acymailing · 1 source · HIGH CVSS 7.5 CVE-2022-23802 Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. guru · 1 source · HIGH CVSS 7.5 CVE-2020-19455 SQL injection exists in the jdownloads 3.2.63 component for Joomla! jdownloads · 1 source · HIGH CVSS 7.5 CVE-2020-19451 SQL injection exists in the jdownloads 3.2.63 component for Joomla! jdownloads · 1 source · HIGH CVSS 7.5 CVE-2020-19450 SQL injection exists in the jdownloads 3.2.63 component for Joomla! jdownloads · 1 source · HIGH CVSS 7.5 CVE-2020-19447 SQL injection exists in the jdownloads 3.2.63 component for Joomla! jdownloads · 1 source · HIGH CVSS 7.5 CVE-2020-25751 The paGO Commerce plugin 2.5.9.0 for Joomla! pago_commerce · 1 source · HIGH CVSS 8.8 CVE-2020-23971 gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. gmapfp · 1 source · HIGH CVSS 7.5 CVE-2020-23972 In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload… gmapfp · 1 source · HIGH CVSS 7.5 CVE-2020-13996 The J2Store plugin before 3.3.13 for Joomla! j2store · 1 source · HIGH CVSS 8.8 CVE-2015-7342 JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field. jnews · 1 source · HIGH CVSS 7.2 CVE-2015-7341 JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. jnews · 1 source · HIGH CVSS 8.8 CVE-2015-7340 JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action. jevents · 1 source · HIGH CVSS 7.2 CVE-2015-7339 JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.p… jce · 1 source · HIGH CVSS 8.8 CVE-2015-7338 SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php. acymailing · 1 source · HIGH CVSS 7.2 CVE-2013-3932 SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! jomres · 1 source · HIGH CVSS 8.8 CVE-2014-1214 views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! smart_flash_header · 1 source · HIGH CVSS 8.8 CVE-2019-9922 An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. je_messenger · 1 source · HIGH CVSS 7.5