Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2022-23799
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2022-23797
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2022-23795
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2021-26040
An issue was discovered in Joomla!
CRITICAL
CVSS 9.1
CVE-2010-1435
Joomla! Core is prone to a security bypass vulnerability.
CRITICAL
CVSS 9.8
CVE-2010-1433
Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input.
CRITICAL
CVSS 9.8
CVE-2021-23128
An issue was discovered in Joomla!
CRITICAL
CVSS 9.1
CVE-2020-35613
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2020-10243
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2011-1151
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
CRITICAL
CVSS 9.1
CVE-2019-19846
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
CRITICAL
CVSS 9.8
CVE-2019-12765
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2019-10945
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2019-7743
Joomla! Object Injection Vulnerability
CRITICAL
CVSS 9.8
CVE-2018-15882
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2018-11325
An issue was discovered in Joomla!
CRITICAL
CVSS 9.8
CVE-2018-6376
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
CRITICAL
CVSS 9.8
CVE-2017-16634
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
CRITICAL
CVSS 9.8
CVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
CRITICAL
CVSS 9.8
CVE-2017-8917
SQL injection vulnerability in Joomla!
CRITICAL
CVSS 9.8