Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

9 résultats

CVE-2026-48940 A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 store… k2 · 1 source · LOW CVSS 3.4 CVE-2025-25228 A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the produc… Virtuemart · 1 source · LOW CVSS 3.8 CVE-2025-22212 A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute… Convert Forms · 1 source · LOW CVSS 2.7 CVE-2025-22211 A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary… JoomShopping · 1 source · LOW CVSS 3.4 CVE-2014-8607 The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! xcloner · 1 source · LOW CVSS 2.1 CVE-2013-5951 Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web sc… Extension Joomla (identification incertaine) · 1 source · LOW CVSS 2.6 CVE-2011-4830 Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! com_listing · 1 source · LOW CVSS 3.5 CVE-2010-3028 The Aardvertiser component before 2.2.1 for Joomla! Extension Joomla (identification incertaine) · 1 source · LOW CVSS 3.6 CVE-2010-0801 Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! com_autartitarot · 1 source · LOW CVSS 3.5