Перейти к содержимому
Noroxi

Записи joomla

986 опубликованных записей вендора joomla.

Профиль для исследователя

Попали в KEV
2 · 0,2 %
С эксплойтом
13 · 1,3 %
Pre-auth RCE
458
С записью об исправлении
3,5 %
Медиана: публикация → KEV
1719 дн.

Все записи

986 записей
  • CVE-2016-10033
    99Срочно

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    phpmailer project · phpmailer30 дек. 2016 г.

  • CVE-2023-23752
    81Срочно

    [20230201] - Core - Improper access check in webservice endpoints

    СредняяCVSS 5,3KEVГотовый эксплойтEPSS 100 %

    joomla · joomla\!16 февр. 2023 г.

  • CVE-2017-8917
    69На этой неделе

    SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %

    joomla · joomla\!17 мая 2017 г.

  • CVE-2016-10045
    68На этой неделе

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e

    КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %

    phpmailer project · phpmailer30 дек. 2016 г.

  • CVE-2016-8869
    68На этой неделе

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote

    КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %

    joomla · joomla\!4 нояб. 2016 г.

  • CVE-2015-7297
    60На этой неделе

    SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 100 %

    joomla · joomla\!29 окт. 2015 г.

  • CVE-2015-8562
    59В плане

    Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via t

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 98 %

    joomla · joomla\!16 дек. 2015 г.

  • CVE-2008-5053
    59В плане

    PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows rem

    КритическаяCVSS 10,0Proof of conceptEPSS 64 %

    joomla · com rssreader13 нояб. 2008 г.

  • CVE-2015-7857
    58В плане

    SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 be

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 94 %

    joomla · joomla\!29 окт. 2015 г.

  • CVE-2015-7858
    56В плане

    SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 86 %

    joomla · joomla\!29 окт. 2015 г.

  • CVE-2016-8870
    56В плане

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registr

    ВысокаяCVSS 8,1Готовый эксплойтEPSS 81 %

    joomla · joomla\!4 нояб. 2016 г.

  • CVE-2019-11358
    50В плане

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp

    СредняяCVSS 6,1Proof of conceptEPSS 87 %

    jquery · jquery19 апр. 2019 г.

  • CVE-2019-10945
    50В плане

    An issue was discovered in Joomla! before 3.9.5.

    КритическаяCVSS 9,8Proof of conceptEPSS 38 %

    joomla · joomla\!10 апр. 2019 г.

  • CVE-2021-26030
    49В плане

    [20210401] - Core - Escape xss in logo parameter error pages

    СредняяCVSS 6,1Эксплойта нетEPSS 82 %

    joomla · joomla\!14 апр. 2021 г.

  • CVE-2021-23124
    48В плане

    [20210102] - Core - XSS in mod_breadcrumbs aria-label attribute

    СредняяCVSS 6,1Эксплойта нетEPSS 79 %

    joomla · joomla\!12 янв. 2021 г.

  • CVE-2020-35613
    48В плане

    [20201104] - Core - SQL injection in com_users list view

    КритическаяCVSS 9,8Эксплойта нетEPSS 29 %

    joomla · joomla\!28 дек. 2020 г.

  • CVE-2014-7228
    47В плане

    Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 55 %

    joomla · joomla\!3 нояб. 2014 г.

  • CVE-2008-6221
    46В плане

    PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remo

    ВысокаяCVSS 7,5Proof of conceptEPSS 54 %

    joomla · joomla20 февр. 2009 г.

  • CVE-2008-1505
    44В плане

    PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote a

    ВысокаяCVSS 7,5Proof of conceptEPSS 46 %

    joomla · joomla25 мар. 2008 г.

  • CVE-2010-5286
    44В плане

    Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly

    КритическаяCVSS 10,0Proof of conceptEPSS 12 %

    joomla · joomla\!26 нояб. 2012 г.

  • CVE-2008-5789
    43В плане

    Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow re

    ВысокаяCVSS 7,5Proof of conceptEPSS 45 %

    recly · interactive feederator31 дек. 2008 г.

  • CVE-2007-5065
    43В плане

    PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote

    ВысокаяCVSS 7,5Proof of conceptEPSS 42 %

    joomla · joomla24 сент. 2007 г.

  • CVE-2018-8045
    43В плане

    In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User

    ВысокаяCVSS 8,8Proof of conceptEPSS 28 %

    joomla · joomla\!14 мар. 2018 г.

  • CVE-2007-1699
    43В плане

    Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo

    КритическаяCVSS 10,0Proof of conceptEPSS 11 %

    joomla · swmenu component26 мар. 2007 г.

  • CVE-2008-4668
    42В плане

    Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and

    КритическаяCVSS 9,0Proof of conceptEPSS 21 %

    joomla · com imagebrowser22 окт. 2008 г.