Skip to main content

Vendor/product archive

joomla / joomla! CVEs

Beta · best-effort

642 CVEs tagged to joomla / joomla!34 Critical, 281 High, 323 Medium, 4 Low, 0 Unrated.

CVE-2009-4576

Published Jan 6, 2010

SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4575

Published Jan 6, 2010

Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4550

Published Jan 4, 2010

SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4475

Published Dec 30, 2009

SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an auction edit a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4255

Published Dec 10, 2009

Cross-site scripting (XSS) vulnerability in the You!Hostit! template 1.0.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the created_by_alias para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4233

Published Dec 8, 2009

Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4232

Published Dec 8, 2009

The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4200

Published Dec 4, 2009

SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_semina…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4157

Published Dec 2, 2009

Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject ar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4104

Published Nov 29, 2009

SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the autho…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4094

Published Nov 29, 2009

PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4059

Published Nov 24, 2009

SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a thumbs action…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4057

Published Nov 24, 2009

SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3972

Published Nov 18, 2009

SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3971

Published Nov 18, 2009

SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3964

Published Nov 18, 2009

SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3946

Published Nov 16, 2009

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3945

Published Nov 16, 2009

Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3822

Published Oct 28, 2009

PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 576-600 of 642 CVEsPage 24 of 26