Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2011-4911

Published Oct 7, 2012

Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4910

Published Oct 7, 2012

Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4909

Published Oct 7, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) compo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5232

Published Oct 1, 2012

Cross-site scripting (XSS) vulnerability in the Quickl Form component for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1117

Published Sep 26, 2012

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1116

Published Sep 26, 2012

SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1612

Published Sep 6, 2012

Cross-site scripting (XSS) vulnerability in the update manager in Joomla! 2.5.x before 2.5.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1611

Published Sep 6, 2012

Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE:…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0837

Published Sep 6, 2012

Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0836

Published Sep 6, 2012

Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0835

Published Sep 6, 2012

Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain sensitive information via unknown vectors related to "administrator."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0822

Published Sep 6, 2012

Cross-site scripting (XSS) vulnerability in Joomla! 1.6 and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0821

Published Sep 6, 2012

Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0820

Published Sep 6, 2012

Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a differen…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0819

Published Sep 6, 2012

Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4868

Published Sep 6, 2012

SQL injection vulnerability in news.php in the Kunena component 1.7.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5148

Published Aug 31, 2012

Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5134

Published Aug 30, 2012

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privi…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5113

Published Aug 23, 2012

SQL injection vulnerability in frontend/models/techfoliodetail.php in Techfolio (com_techfolio) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5112

Published Aug 23, 2012

SQL injection vulnerability in Alameda (com_alameda) component before 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the storeid parameter to inde…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4256

Published Aug 13, 2012

The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 974 CVEsPage 12 of 39