Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2011-2890
The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla!
MEDIUM
CVSS 5.0
CVE-2011-2889
templates/system/error.php in Joomla!
MEDIUM
CVSS 5.0
CVE-2011-2710
Multiple cross-site scripting (XSS) vulnerabilities in Joomla!
MEDIUM
CVSS 4.3
CVE-2011-2509
Joomla! vulnerable to Cross-site Scripting
MEDIUM
CVSS 4.3
CVE-2011-2488
Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.
MEDIUM
CVSS 5.0
CVE-2010-3712
Cross-site scripting (XSS) vulnerability in Joomla!
MEDIUM
CVSS 4.3
CVE-2010-1649
Joomla! vulnerable to Cross-site Scripting
MEDIUM
CVSS 4.3
CVE-2009-3946
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
MEDIUM
CVSS 5.0
CVE-2009-3945
Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla!
MEDIUM
CVSS 5.5
CVE-2009-1940
Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-1939
Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla!
MEDIUM
CVSS 4.3
CVE-2009-1938
Cross-site scripting (XSS) vulnerability in Joomla!
MEDIUM
CVSS 4.3
CVE-2009-1280
Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla!
MEDIUM
CVSS 6.8
CVE-2008-4107
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in pro…
MEDIUM
CVSS 5.1
CVE-2008-4104
Joomla! Open Redirect vulnerability
MEDIUM
CVSS 5.8
CVE-2008-3226
Joomla! allows attackers to access cached pages
MEDIUM
CVSS 5.0
CVE-2008-1533
Unspecified vulnerability in the XML-RPC Blogger API plugin in Joomla!
MEDIUM
CVSS 6.8
CVE-2007-6644
Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security…
MEDIUM
CVSS 6.5
CVE-2007-6643
Cross-site scripting (XSS) vulnerability in the com_poll component in Joomla!
MEDIUM
CVSS 4.3
CVE-2007-6642
Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla!
MEDIUM
CVSS 6.8