Joomla ! vulnerabilities
276 known vulnerabilities affecting joomla/joomla_!.
Total CVEs
276
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH68MEDIUM176LOW2
Vulnerabilities
Page 12 of 14
CVE-2013-3267MEDIUMCVSS 4.3v2.5.0v2.5.1+12 more2013-05-03
CVE-2013-3267 [MEDIUM] CWE-79 CVE-2013-3267: Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 an
Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-1453HIGHCVSS 7.5PoCv2.5.0v2.5.1+10 more2013-02-13
CVE-2013-1453 [HIGH] CVE-2013-1453: plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows
plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete arbitrary directories, conduct SQL injection attacks, and possibly have other impacts via the highlight parameter. Note: it was originally reported that this issue only allowe
nvd
CVE-2013-1455MEDIUMCVSS 5.0v3.0.0v3.0.12013-02-13
CVE-2013-1455 [MEDIUM] CWE-200 CVE-2013-1455: Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors
Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable."
nvd
CVE-2013-1454MEDIUMCVSS 5.0v3.0.0v3.0.1+1 more2013-02-13
CVE-2013-1454 [MEDIUM] CWE-200 CVE-2013-1454: Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors
Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors."
nvd
CVE-2012-1598HIGHCVSS 7.5v1.5.0v1.5.1+24 more2012-12-03
CVE-2012-1598 [HIGH] CWE-264 CVE-2012-1598: Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient rando
Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."
nvd
CVE-2012-1599MEDIUMCVSS 5.0v1.5.0v1.5.1+24 more2012-12-03
CVE-2012-1599 [MEDIUM] CWE-264 CVE-2012-1599: Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain se
Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a duplicate of CVE-2012-1611.
nvd
CVE-2012-5827MEDIUMCVSS 4.3v2.5.0v2.5.1+6 more2012-11-11
CVE-2012-5827 [MEDIUM] CVE-2012-5827: Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking at
Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors involving "Inadequate protection."
nvd
CVE-2012-4531MEDIUMCVSS 4.3v2.5.0v2.5.1+5 more2012-10-31
CVE-2012-4531 [MEDIUM] CWE-79 CVE-2012-4531: Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to in
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-4532MEDIUMCVSS 4.3v2.5.0v2.5.1+5 more2012-10-31
CVE-2012-4532 [MEDIUM] CWE-79 CVE-2012-4532: Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language S
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. NOTE: some of these details are obtained from third party information.
nvd
CVE-2012-5455MEDIUMCVSS 4.3v3.0.02012-10-22
CVE-2012-5455 [MEDIUM] CWE-79 CVE-2012-5455: Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 al
Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "typographical error."
nvd
CVE-2011-4911MEDIUMCVSS 5.0≤ 1.5.11v1.5.0+10 more2012-10-07
CVE-2011-4911 [MEDIUM] CWE-20 CVE-2011-4911: Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attac
Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.
nvd
CVE-2011-4910MEDIUMCVSS 4.3≤ 1.5.11v1.5.0+10 more2012-10-07
CVE-2011-4910 [MEDIUM] CWE-79 CVE-2011-4910: Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12 allows remote attackers to inject
Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
nvd
CVE-2011-4909MEDIUMCVSS 4.3PoC≤ 1.5.11v1.5.0+10 more2012-10-07
CVE-2011-4909 [MEDIUM] CWE-79 CVE-2011-4909: Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.p
nvd
CVE-2012-1116HIGHCVSS 7.5PoCv1.7.0v1.7.1+6 more2012-09-26
CVE-2012-1116 [HIGH] CWE-89 CVE-2012-1116: SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execu
SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-1117MEDIUMCVSS 4.3v2.5.0v2.5.12012-09-26
CVE-2012-1117 [MEDIUM] CWE-79 CVE-2012-1117: Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to injec
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-0819MEDIUMCVSS 5.0v1.6v1.6.0+9 more2012-09-06
CVE-2012-0819 [MEDIUM] CVE-2012-0819: Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain
Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0821.
nvd
CVE-2012-0835MEDIUMCVSS 5.0v1.7.0v1.7.1+4 more2012-09-06
CVE-2012-0835 [MEDIUM] CVE-2012-0835: Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to o
Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain sensitive information via unknown vectors related to "administrator."
nvd
CVE-2012-1611MEDIUMCVSS 5.0v2.5.0v2.5.1+2 more2012-09-06
CVE-2012-1611 [MEDIUM] CVE-2012-1611: Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sen
Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE: this might be a duplicate of CVE-2012-1599.
nvd
CVE-2012-0820MEDIUMCVSS 4.3v1.6v1.6.0+9 more2012-09-06
CVE-2012-0820 [MEDIUM] CWE-79 CVE-2012-0820: Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attac
Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0822.
nvd
CVE-2012-0821MEDIUMCVSS 5.0v1.6v1.6.0+9 more2012-09-06
CVE-2012-0821 [MEDIUM] CVE-2012-0821: Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain
Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0819.
nvd