Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

23 résultats

CVE-2022-23799 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2022-23797 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2022-23795 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2021-26040 An issue was discovered in Joomla! Joomla CMS · 2 sources · CRITICAL CVSS 9.1 CVE-2010-1435 Joomla! Core is prone to a security bypass vulnerability. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2010-1433 Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2021-23128 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.1 CVE-2020-35613 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2020-10243 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2011-1151 Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. Joomla CMS · 1 source · CRITICAL CVSS 9.1 CVE-2019-19846 In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2019-12765 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2019-10945 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2019-7743 Joomla! Object Injection Vulnerability Joomla CMS · 3 sources · CRITICAL CVSS 9.8 CVE-2018-15882 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2018-11325 An issue was discovered in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2018-6376 In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2017-16634 In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2017-14596 In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. Joomla CMS · 1 source · CRITICAL CVSS 9.8 CVE-2017-8917 SQL injection vulnerability in Joomla! Joomla CMS · 1 source · CRITICAL CVSS 9.8