Joomla ! vulnerabilities
276 known vulnerabilities affecting joomla/joomla_!.
Total CVEs
276
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH68MEDIUM176LOW2
Vulnerabilities
Page 14 of 14
CVE-2010-3712MEDIUMCVSS 4.3v1.5.0v1.5.1+19 more2010-10-28
CVE-2010-3712 [MEDIUM] CWE-79 CVE-2010-3712: Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allow
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.php in the com_weblinks or com_content component.
nvd
CVE-2010-2535LOWCVSS 3.5v1.5.0v1.5.1+18 more2010-10-05
CVE-2010-2535 [LOW] CWE-79 CVE-2010-2535: Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 a
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.
nvd
CVE-2010-1649MEDIUMCVSS 4.3v1.5.0v1.5.1+16 more2010-06-08
CVE-2010-1649 [MEDIUM] CWE-79 CVE-2010-1649: Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 al
Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "various administrator screens," possibly the search parameter in administrator/index.php.
nvd
CVE-2009-3945MEDIUMCVSS 5.5≤ 1.5.14v1.5.0+13 more2009-11-16
CVE-2009-3945 [MEDIUM] CVE-2009-3945: Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5
Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.
nvd
CVE-2009-3946MEDIUMCVSS 5.0≤ 1.5.14v1.5.0+13 more2009-11-16
CVE-2009-3946 [MEDIUM] CWE-200 CVE-2009-3946: Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain th
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
nvd
CVE-2008-4122HIGHCVSS 7.5v1.5.82008-12-19
CVE-2008-4122 [HIGH] CWE-319 CVE-2008-4122: Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes i
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2007-5577MEDIUMCVSS 4.3fixed in 1.0.132007-10-18
CVE-2007-5577 [MEDIUM] CWE-79 CVE-2007-5577: Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow rem
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item.
nvd
CVE-2007-4188CRITICALCVSS 9.3fixed in 1.0.132007-08-08
CVE-2007-4188 [CRITICAL] CWE-384 CVE-2007-4188: Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hij
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
nvd
CVE-2007-4190MEDIUMCVSS 4.3fixed in 1.0.132007-08-08
CVE-2007-4190 [MEDIUM] CWE-74 CVE-2007-4190: CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to injec
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party informati
nvd
CVE-2007-4189MEDIUMCVSS 4.3fixed in 1.0.132007-08-08
CVE-2007-4189 [MEDIUM] CWE-79 CVE-2007-4189: Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow rem
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search, (2) com_content, and (3) mod_login components. NOTE: some of these details are obtained from third party information.
nvd
CVE-2006-4472HIGHCVSS 7.5fixed in 1.0.112006-08-31
CVE-2006-4472 [HIGH] CVE-2006-4472: Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authent
Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.
nvd
CVE-2006-4469HIGHCVSS 7.5fixed in 1.0.112006-08-31
CVE-2006-4469 [HIGH] CVE-2006-4469: Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "r
Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."
nvd
CVE-2006-4470HIGHCVSS 7.5fixed in 1.0.112006-08-31
CVE-2006-4470 [HIGH] CVE-2006-4470: Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to
Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.
nvd
CVE-2006-4471MEDIUMCVSS 6.5fixed in 1.0.112006-08-31
CVE-2006-4471 [MEDIUM] CWE-434 CVE-2006-4471: The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to u
The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.
nvd
CVE-2006-4468MEDIUMCVSS 6.8fixed in 1.0.112006-08-31
CVE-2006-4468 [MEDIUM] CWE-20 CVE-2006-4468: Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow a
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll
nvd
CVE-2005-4650MEDIUMCVSS 5.3v1.0.32005-12-31
CVE-2005-4650 [MEDIUM] CWE-770 CVE-2005-4650: Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to caus
Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.
nvd
← Previous14 / 14