Записи joomla
986 опубликованных записей вендора joomla.
Профиль для исследователя
- Попали в KEV
- 2 · 0,2 %
- С эксплойтом
- 13 · 1,3 %
- Pre-auth RCE
- 458
- С записью об исправлении
- 3,5 %
- Медиана: публикация → KEV
- 1719 дн.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')362
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')161
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')125
- CWE-94 Improper Control of Generation of Code ('Code Injection')51
- CWE-20 Improper Input Validation25
- CWE-284 Improper Access Control24
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
986 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2016-10033Готовый эксплойт | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Критическая9,8 | KEV | 99,7 % | 30 дек. 2016 г. |
81Срочно | CVE-2023-23752Готовый эксплойт | [20230201] - Core - Improper access check in webservice endpointsjoomla · joomla\! · CWE-284 | Средняя5,3 | KEV | 99,8 % | 16 февр. 2023 г. |
69На этой неделе | CVE-2017-8917Готовый эксплойт | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.joomla · joomla\! · CWE-89 | Критическая9,8 | — | 99,8 % | 17 мая 2017 г. |
68На этой неделе | CVE-2016-10045Готовый эксплойт | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently ephpmailer project · phpmailer · CWE-77 | Критическая9,8 | — | 97,7 % | 30 дек. 2016 г. |
68На этой неделе | CVE-2016-8869Готовый эксплойт | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remotejoomla · joomla\! · CWE-20 | Критическая9,8 | — | 97,3 % | 4 нояб. 2016 г. |
60На этой неделе | CVE-2015-7297Готовый эксплойт | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, ajoomla · joomla\! · CWE-89 | Высокая7,5 | — | 100,0 % | 29 окт. 2015 г. |
59В плане | CVE-2015-8562Готовый эксплойт | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via tjoomla · joomla\! · CWE-20 | Высокая7,5 | — | 98,3 % | 16 дек. 2015 г. |
59В плане | CVE-2008-5053Proof of concept | PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remjoomla · com rssreader · CWE-94 | Критическая10,0 | — | 64,1 % | 13 нояб. 2008 г. |
58В плане | CVE-2015-7857Готовый эксплойт | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 bejoomla · joomla\! · CWE-89 | Высокая7,5 | — | 94,5 % | 29 окт. 2015 г. |
56В плане | CVE-2015-7858Готовый эксплойт | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, ajoomla · joomla\! · CWE-89 | Высокая7,5 | — | 85,6 % | 29 окт. 2015 г. |
56В плане | CVE-2016-8870Готовый эксплойт | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registrjoomla · joomla\! · CWE-20 | Высокая8,1 | — | 81,1 % | 4 нояб. 2016 г. |
50В плане | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Средняя6,1 | — | 87,2 % | 19 апр. 2019 г. |
50В плане | CVE-2019-10945Proof of concept | An issue was discovered in Joomla! before 3.9.5.joomla · joomla\! · CWE-22 | Критическая9,8 | — | 38,0 % | 10 апр. 2019 г. |
49В плане | CVE-2021-26030Эксплойта нет | [20210401] - Core - Escape xss in logo parameter error pagesjoomla · joomla\! · CWE-79 | Средняя6,1 | — | 82,3 % | 14 апр. 2021 г. |
48В плане | CVE-2021-23124Эксплойта нет | [20210102] - Core - XSS in mod_breadcrumbs aria-label attributejoomla · joomla\! · CWE-79 | Средняя6,1 | — | 79,0 % | 12 янв. 2021 г. |
48В плане | CVE-2020-35613Эксплойта нет | [20201104] - Core - SQL injection in com_users list viewjoomla · joomla\! · CWE-89 | Критическая9,8 | — | 28,9 % | 28 дек. 2020 г. |
47В плане | CVE-2014-7228Готовый эксплойт | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!joomla · joomla\! · CWE-310 | Высокая7,5 | — | 55,4 % | 3 нояб. 2014 г. |
46В плане | CVE-2008-6221Proof of concept | PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remojoomla · joomla · CWE-94 | Высокая7,5 | — | 54,0 % | 20 февр. 2009 г. |
44В плане | CVE-2008-1505Proof of concept | PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote ajoomla · joomla · CWE-94 | Высокая7,5 | — | 46,1 % | 25 мар. 2008 г. |
44В плане | CVE-2010-5286Proof of concept | Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly joomla · joomla\! · CWE-22 | Критическая10,0 | — | 12,1 % | 26 нояб. 2012 г. |
43В плане | CVE-2008-5789Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow rerecly · interactive feederator · CWE-94 | Высокая7,5 | — | 45,0 % | 31 дек. 2008 г. |
43В плане | CVE-2007-5065Proof of concept | PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote joomla · joomla · CWE-94 | Высокая7,5 | — | 42,3 % | 24 сент. 2007 г. |
43В плане | CVE-2018-8045Proof of concept | In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Userjoomla · joomla\! · CWE-89 | Высокая8,8 | — | 28,2 % | 14 мар. 2018 г. |
43В плане | CVE-2007-1699Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allojoomla · swmenu component | Критическая10,0 | — | 10,6 % | 26 мар. 2007 г. |
42В плане | CVE-2008-4668Proof of concept | Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include andjoomla · com imagebrowser · CWE-22 | Критическая9,0 | — | 21,5 % | 22 окт. 2008 г. |
- CVE-2016-1003399Срочно
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %phpmailer project · phpmailer30 дек. 2016 г.
- CVE-2023-2375281Срочно
[20230201] - Core - Improper access check in webservice endpoints
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 100 %joomla · joomla\!16 февр. 2023 г.
- CVE-2017-891769На этой неделе
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %joomla · joomla\!17 мая 2017 г.
- CVE-2016-1004568На этой неделе
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e
КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %phpmailer project · phpmailer30 дек. 2016 г.
- CVE-2016-886968На этой неделе
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %joomla · joomla\!4 нояб. 2016 г.
- CVE-2015-729760На этой неделе
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a
ВысокаяCVSS 7,5Готовый эксплойтEPSS 100 %joomla · joomla\!29 окт. 2015 г.
- CVE-2015-856259В плане
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via t
ВысокаяCVSS 7,5Готовый эксплойтEPSS 98 %joomla · joomla\!16 дек. 2015 г.
- CVE-2008-505359В плане
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows rem
КритическаяCVSS 10,0Proof of conceptEPSS 64 %joomla · com rssreader13 нояб. 2008 г.
- CVE-2015-785758В плане
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 be
ВысокаяCVSS 7,5Готовый эксплойтEPSS 94 %joomla · joomla\!29 окт. 2015 г.
- CVE-2015-785856В плане
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a
ВысокаяCVSS 7,5Готовый эксплойтEPSS 86 %joomla · joomla\!29 окт. 2015 г.
- CVE-2016-887056В плане
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registr
ВысокаяCVSS 8,1Готовый эксплойтEPSS 81 %joomla · joomla\!4 нояб. 2016 г.
- CVE-2019-1135850В плане
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
СредняяCVSS 6,1Proof of conceptEPSS 87 %jquery · jquery19 апр. 2019 г.
- CVE-2019-1094550В плане
An issue was discovered in Joomla! before 3.9.5.
КритическаяCVSS 9,8Proof of conceptEPSS 38 %joomla · joomla\!10 апр. 2019 г.
- CVE-2021-2603049В плане
[20210401] - Core - Escape xss in logo parameter error pages
СредняяCVSS 6,1Эксплойта нетEPSS 82 %joomla · joomla\!14 апр. 2021 г.
- CVE-2021-2312448В плане
[20210102] - Core - XSS in mod_breadcrumbs aria-label attribute
СредняяCVSS 6,1Эксплойта нетEPSS 79 %joomla · joomla\!12 янв. 2021 г.
- CVE-2020-3561348В плане
[20201104] - Core - SQL injection in com_users list view
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %joomla · joomla\!28 дек. 2020 г.
- CVE-2014-722847В плане
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!
ВысокаяCVSS 7,5Готовый эксплойтEPSS 55 %joomla · joomla\!3 нояб. 2014 г.
- CVE-2008-622146В плане
PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remo
ВысокаяCVSS 7,5Proof of conceptEPSS 54 %joomla · joomla20 февр. 2009 г.
- CVE-2008-150544В плане
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote a
ВысокаяCVSS 7,5Proof of conceptEPSS 46 %joomla · joomla25 мар. 2008 г.
- CVE-2010-528644В плане
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly
КритическаяCVSS 10,0Proof of conceptEPSS 12 %joomla · joomla\!26 нояб. 2012 г.
- CVE-2008-578943В плане
Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow re
ВысокаяCVSS 7,5Proof of conceptEPSS 45 %recly · interactive feederator31 дек. 2008 г.
- CVE-2007-506543В плане
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote
ВысокаяCVSS 7,5Proof of conceptEPSS 42 %joomla · joomla24 сент. 2007 г.
- CVE-2018-804543В плане
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User
ВысокаяCVSS 8,8Proof of conceptEPSS 28 %joomla · joomla\!14 мар. 2018 г.
- CVE-2007-169943В плане
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo
КритическаяCVSS 10,0Proof of conceptEPSS 11 %joomla · swmenu component26 мар. 2007 г.
- CVE-2008-466842В плане
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and
КритическаяCVSS 9,0Proof of conceptEPSS 21 %joomla · com imagebrowser22 окт. 2008 г.