Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2025-25227
Joomla CMS Multi-Factor Authentication Bypass
HIGH
CVSS 7.5
CVE-2025-22210
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL…
HIGH
CVSS 7.2
CVE-2025-22205
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
HIGH
CVSS 7.5
CVE-2024-5736
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla!
HIGH
CVSS 8.2
CVE-2023-23755
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2023-28732
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system…
HIGH
CVSS 7.5
CVE-2022-23802
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions.
HIGH
CVSS 7.5
CVE-2022-23793
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2021-26036
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2021-26038
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2010-1434
Joomla! Core is prone to a session fixation vulnerability.
HIGH
CVSS 7.5
CVE-2010-1432
Joomla! Core is prone to an information disclosure vulnerability.
HIGH
CVSS 7.5
CVE-2021-23132
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2021-23131
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35616
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35612
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35611
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35610
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-19455
SQL injection exists in the jdownloads 3.2.63 component for Joomla!
HIGH
CVSS 7.5
CVE-2020-19451
SQL injection exists in the jdownloads 3.2.63 component for Joomla!
HIGH
CVSS 7.5