Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-48947
Incorrect Access Control in com_media webservice endpoints
LOW
CVE-2026-48948
Incorrect Access Control in com_contact vcf download
LOW
CVE-2026-48940
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 store…
LOW
CVSS 3.4
CVE-2026-48902
Transport encryption downgrade for password and username reset links
LOW
CVE-2025-25228
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the produc…
LOW
CVSS 3.8
CVE-2025-22212
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute…
LOW
CVSS 2.7
CVE-2025-22211
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary…
LOW
CVSS 3.4
CVE-2017-14595
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
LOW
CVSS 3.7
CVE-2014-8607
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla!
LOW
CVSS 2.1
CVE-2013-5951
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web sc…
LOW
CVSS 2.6
CVE-2011-4830
Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla!
LOW
CVSS 3.5
CVE-2010-2535
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla!
LOW
CVSS 3.5
CVE-2010-3028
The Aardvertiser component before 2.2.1 for Joomla!
LOW
CVSS 3.6
CVE-2010-0801
Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla!
LOW
CVSS 3.5
CVE-2009-1279
Multiple cross-site scripting (XSS) vulnerabilities in Joomla!
LOW
CVSS 2.6
CVE-2008-6299
Multiple cross-site scripting (XSS) vulnerabilities in Joomla!
LOW
CVSS 3.5