Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2020-13760

Published Jun 2, 2020

In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11891

Published Apr 21, 2020

An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11890

Published Apr 21, 2020

An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11889

Published Apr 21, 2020

An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10243

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles fronten…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10242

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10241

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10240

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10239

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10238

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1151

Published Feb 5, 2020

Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4912

Published Feb 4, 2020

Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4937

Published Feb 4, 2020

Joomla! 1.7.1 has core information disclosure due to inadequate error checking.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3629

Published Feb 4, 2020

Joomla! core 1.7.1 allows information disclosure due to weak encryption

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8421

Published Jan 28, 2020

An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8420

Published Jan 28, 2020

An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8419

Published Jan 28, 2020

An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3595

Published Jan 22, 2020

Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19846

Published Dec 18, 2019

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19845

Published Dec 18, 2019

In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18674

Published Nov 6, 2019

An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18650

Published Nov 6, 2019

An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 974 CVEsPage 6 of 39