Filtered by vendor Joomla
Subscriptions
Filtered by product Joomla\!
Subscriptions
Total
583 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-13760 | 1 Joomla | 1 Joomla\! | 2020-10-19 | 8.8 High |
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. | ||||
CVE-2020-13761 | 1 Joomla | 1 Joomla\! | 2020-10-19 | 6.1 Medium |
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS. | ||||
CVE-2020-24598 | 1 Joomla | 1 Joomla\! | 2020-08-28 | 6.1 Medium |
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. | ||||
CVE-2020-24599 | 1 Joomla | 1 Joomla\! | 2020-08-28 | 6.1 Medium |
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. | ||||
CVE-2019-7743 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files. | ||||
CVE-2019-7739 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this. | ||||
CVE-2019-14654 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9. | ||||
CVE-2019-15028 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. | ||||
CVE-2019-10946 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users. | ||||
CVE-2018-17855 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself. | ||||
CVE-2019-9713 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access. | ||||
CVE-2018-17856 | 1 Joomla | 1 Joomla\! | 2020-08-24 | N/A |
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution. | ||||
CVE-2020-15700 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 6.3 Medium |
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. | ||||
CVE-2020-15699 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 5.3 Medium |
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. | ||||
CVE-2020-15697 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 4.3 Medium |
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users. | ||||
CVE-2020-15695 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 6.3 Medium |
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. | ||||
CVE-2020-15696 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 6.1 Medium |
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. | ||||
CVE-2020-13762 | 1 Joomla | 1 Joomla\! | 2020-06-03 | 6.1 Medium |
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. | ||||
CVE-2020-11890 | 1 Joomla | 1 Joomla\! | 2020-04-29 | 5.3 Medium |
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. | ||||
CVE-2020-10238 | 1 Joomla | 1 Joomla\! | 2020-03-19 | 7.5 High |
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors. |