joomla kayıtları
joomla üreticisine ait 986 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,2
- Silahlaştırılmış
- 13 · %1,3
- Pre-auth RCE
- 458
- Düzeltme kaydı olan
- %3,5
- Yayından KEV’e ortanca
- 1719 gün
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')362
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')161
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')125
- CWE-94 Improper Control of Generation of Code ('Code Injection')51
- CWE-20 Improper Input Validation25
- CWE-284 Improper Access Control24
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
986 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2016-10033Silahlaştırılmış | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Kritik9,8 | KEV | %99,7 | 30 Ara 2016 |
81Hemen | CVE-2023-23752Silahlaştırılmış | [20230201] - Core - Improper access check in webservice endpointsjoomla · joomla\! · CWE-284 | Orta5,3 | KEV | %99,8 | 16 Şub 2023 |
69Bu hafta | CVE-2017-8917Silahlaştırılmış | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.joomla · joomla\! · CWE-89 | Kritik9,8 | — | %99,8 | 17 May 2017 |
68Bu hafta | CVE-2016-10045Silahlaştırılmış | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently ephpmailer project · phpmailer · CWE-77 | Kritik9,8 | — | %97,7 | 30 Ara 2016 |
68Bu hafta | CVE-2016-8869Silahlaştırılmış | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remotejoomla · joomla\! · CWE-20 | Kritik9,8 | — | %97,3 | 4 Kas 2016 |
60Bu hafta | CVE-2015-7297Silahlaştırılmış | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, ajoomla · joomla\! · CWE-89 | Yüksek7,5 | — | %100,0 | 29 Eki 2015 |
59Planlayın | CVE-2015-8562Silahlaştırılmış | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via tjoomla · joomla\! · CWE-20 | Yüksek7,5 | — | %98,3 | 16 Ara 2015 |
59Planlayın | CVE-2008-5053Kavram kanıtı | PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remjoomla · com rssreader · CWE-94 | Kritik10,0 | — | %64,1 | 13 Kas 2008 |
58Planlayın | CVE-2015-7857Silahlaştırılmış | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 bejoomla · joomla\! · CWE-89 | Yüksek7,5 | — | %94,5 | 29 Eki 2015 |
56Planlayın | CVE-2015-7858Silahlaştırılmış | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, ajoomla · joomla\! · CWE-89 | Yüksek7,5 | — | %85,6 | 29 Eki 2015 |
56Planlayın | CVE-2016-8870Silahlaştırılmış | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registrjoomla · joomla\! · CWE-20 | Yüksek8,1 | — | %81,1 | 4 Kas 2016 |
50Planlayın | CVE-2019-11358Kavram kanıtı | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Orta6,1 | — | %87,2 | 19 Nis 2019 |
50Planlayın | CVE-2019-10945Kavram kanıtı | An issue was discovered in Joomla! before 3.9.5.joomla · joomla\! · CWE-22 | Kritik9,8 | — | %38,0 | 10 Nis 2019 |
49Planlayın | CVE-2021-26030İstismar yok | [20210401] - Core - Escape xss in logo parameter error pagesjoomla · joomla\! · CWE-79 | Orta6,1 | — | %82,3 | 14 Nis 2021 |
48Planlayın | CVE-2021-23124İstismar yok | [20210102] - Core - XSS in mod_breadcrumbs aria-label attributejoomla · joomla\! · CWE-79 | Orta6,1 | — | %79,0 | 12 Oca 2021 |
48Planlayın | CVE-2020-35613İstismar yok | [20201104] - Core - SQL injection in com_users list viewjoomla · joomla\! · CWE-89 | Kritik9,8 | — | %28,9 | 28 Ara 2020 |
47Planlayın | CVE-2014-7228Silahlaştırılmış | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!joomla · joomla\! · CWE-310 | Yüksek7,5 | — | %55,4 | 3 Kas 2014 |
44Planlayın | CVE-2008-1505Kavram kanıtı | PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote ajoomla · joomla · CWE-94 | Yüksek7,5 | — | %46,1 | 25 Mar 2008 |
44Planlayın | CVE-2010-5286Kavram kanıtı | Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly joomla · joomla\! · CWE-22 | Kritik10,0 | — | %12,1 | 26 Kas 2012 |
43Planlayın | CVE-2008-5789Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow rerecly · interactive feederator · CWE-94 | Yüksek7,5 | — | %45,0 | 31 Ara 2008 |
43Planlayın | CVE-2007-5065Kavram kanıtı | PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote joomla · joomla · CWE-94 | Yüksek7,5 | — | %42,3 | 24 Eyl 2007 |
43Planlayın | CVE-2018-8045Kavram kanıtı | In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Userjoomla · joomla\! · CWE-89 | Yüksek8,8 | — | %28,2 | 14 Mar 2018 |
43Planlayın | CVE-2007-1699Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allojoomla · swmenu component | Kritik10,0 | — | %10,6 | 26 Mar 2007 |
42Planlayın | CVE-2008-4668Kavram kanıtı | Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include andjoomla · com imagebrowser · CWE-22 | Kritik9,0 | — | %21,5 | 22 Eki 2008 |
42Planlayın | CVE-2019-12765Kavram kanıtı | An issue was discovered in Joomla! before 3.9.7.joomla · joomla\! · CWE-1236 | Kritik9,8 | — | %10,5 | 11 Haz 2019 |
- CVE-2016-1003399Hemen
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100phpmailer project · phpmailer30 Ara 2016
- CVE-2023-2375281Hemen
[20230201] - Core - Improper access check in webservice endpoints
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %100joomla · joomla\!16 Şub 2023
- CVE-2017-891769Bu hafta
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
KritikCVSS 9,8SilahlaştırılmışEPSS %100joomla · joomla\!17 May 2017
- CVE-2016-1004568Bu hafta
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e
KritikCVSS 9,8SilahlaştırılmışEPSS %98phpmailer project · phpmailer30 Ara 2016
- CVE-2016-886968Bu hafta
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote
KritikCVSS 9,8SilahlaştırılmışEPSS %97joomla · joomla\!4 Kas 2016
- CVE-2015-729760Bu hafta
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a
YüksekCVSS 7,5SilahlaştırılmışEPSS %100joomla · joomla\!29 Eki 2015
- CVE-2015-856259Planlayın
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via t
YüksekCVSS 7,5SilahlaştırılmışEPSS %98joomla · joomla\!16 Ara 2015
- CVE-2008-505359Planlayın
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows rem
KritikCVSS 10,0Kavram kanıtıEPSS %64joomla · com rssreader13 Kas 2008
- CVE-2015-785758Planlayın
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 be
YüksekCVSS 7,5SilahlaştırılmışEPSS %94joomla · joomla\!29 Eki 2015
- CVE-2015-785856Planlayın
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a
YüksekCVSS 7,5SilahlaştırılmışEPSS %86joomla · joomla\!29 Eki 2015
- CVE-2016-887056Planlayın
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registr
YüksekCVSS 8,1SilahlaştırılmışEPSS %81joomla · joomla\!4 Kas 2016
- CVE-2019-1135850Planlayın
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
OrtaCVSS 6,1Kavram kanıtıEPSS %87jquery · jquery19 Nis 2019
- CVE-2019-1094550Planlayın
An issue was discovered in Joomla! before 3.9.5.
KritikCVSS 9,8Kavram kanıtıEPSS %38joomla · joomla\!10 Nis 2019
- CVE-2021-2603049Planlayın
[20210401] - Core - Escape xss in logo parameter error pages
OrtaCVSS 6,1İstismar yokEPSS %82joomla · joomla\!14 Nis 2021
- CVE-2021-2312448Planlayın
[20210102] - Core - XSS in mod_breadcrumbs aria-label attribute
OrtaCVSS 6,1İstismar yokEPSS %79joomla · joomla\!12 Oca 2021
- CVE-2020-3561348Planlayın
[20201104] - Core - SQL injection in com_users list view
KritikCVSS 9,8İstismar yokEPSS %29joomla · joomla\!28 Ara 2020
- CVE-2014-722847Planlayın
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!
YüksekCVSS 7,5SilahlaştırılmışEPSS %55joomla · joomla\!3 Kas 2014
- CVE-2008-150544Planlayın
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote a
YüksekCVSS 7,5Kavram kanıtıEPSS %46joomla · joomla25 Mar 2008
- CVE-2010-528644Planlayın
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly
KritikCVSS 10,0Kavram kanıtıEPSS %12joomla · joomla\!26 Kas 2012
- CVE-2008-578943Planlayın
Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow re
YüksekCVSS 7,5Kavram kanıtıEPSS %45recly · interactive feederator31 Ara 2008
- CVE-2007-506543Planlayın
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote
YüksekCVSS 7,5Kavram kanıtıEPSS %42joomla · joomla24 Eyl 2007
- CVE-2018-804543Planlayın
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User
YüksekCVSS 8,8Kavram kanıtıEPSS %28joomla · joomla\!14 Mar 2018
- CVE-2007-169943Planlayın
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo
KritikCVSS 10,0Kavram kanıtıEPSS %11joomla · swmenu component26 Mar 2007
- CVE-2008-466842Planlayın
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and
KritikCVSS 9,0Kavram kanıtıEPSS %21joomla · com imagebrowser22 Eki 2008
- CVE-2019-1276542Planlayın
An issue was discovered in Joomla! before 3.9.7.
KritikCVSS 9,8Kavram kanıtıEPSS %10joomla · joomla\!11 Haz 2019