Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2014-0793

Published Jan 30, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0794

Published Jan 26, 2014

SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5583

Published Dec 29, 2013

Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5576

Published Oct 9, 2013

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3719

Published May 31, 2013

Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3534

Published May 13, 2013

Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3267

Published May 3, 2013

Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3242

Published May 3, 2013

plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3059

Published May 3, 2013

Cross-site scripting (XSS) vulnerability in the Voting plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3058

Published May 3, 2013

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3057

Published May 3, 2013

Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and list the privileges of arbitrary users via unspe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3056

Published May 3, 2013

Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and delete the private messages of arbitrary users v…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1455

Published Feb 13, 2013

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1454

Published Feb 13, 2013

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1453

Published Feb 13, 2013

plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1599

Published Dec 3, 2012

Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1598

Published Dec 3, 2012

Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5286

Published Nov 26, 2012

Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-5280

Published Nov 26, 2012

Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5827

Published Nov 11, 2012

Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors involving "Inadequate protection."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4532

Published Oct 31, 2012

Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4531

Published Oct 31, 2012

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5455

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 974 CVEsPage 11 of 39