Filtered by vendor Joomla Subscriptions
Filtered by product Joomla\! Subscriptions
Total 583 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-13760 1 Joomla 1 Joomla\! 2020-10-19 8.8 High
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
CVE-2020-13761 1 Joomla 1 Joomla\! 2020-10-19 6.1 Medium
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
CVE-2020-24598 1 Joomla 1 Joomla\! 2020-08-28 6.1 Medium
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
CVE-2020-24599 1 Joomla 1 Joomla\! 2020-08-28 6.1 Medium
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
CVE-2019-7743 1 Joomla 1 Joomla\! 2020-08-24 N/A
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
CVE-2019-7739 1 Joomla 1 Joomla\! 2020-08-24 N/A
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this.
CVE-2019-14654 1 Joomla 1 Joomla\! 2020-08-24 N/A
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.
CVE-2019-15028 1 Joomla 1 Joomla\! 2020-08-24 N/A
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
CVE-2019-10946 1 Joomla 1 Joomla\! 2020-08-24 N/A
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.
CVE-2018-17855 1 Joomla 1 Joomla\! 2020-08-24 N/A
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
CVE-2019-9713 1 Joomla 1 Joomla\! 2020-08-24 N/A
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
CVE-2018-17856 1 Joomla 1 Joomla\! 2020-08-24 N/A
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
CVE-2020-15700 1 Joomla 1 Joomla\! 2020-07-15 6.3 Medium
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
CVE-2020-15699 1 Joomla 1 Joomla\! 2020-07-15 5.3 Medium
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
CVE-2020-15697 1 Joomla 1 Joomla\! 2020-07-15 4.3 Medium
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
CVE-2020-15695 1 Joomla 1 Joomla\! 2020-07-15 6.3 Medium
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
CVE-2020-15696 1 Joomla 1 Joomla\! 2020-07-15 6.1 Medium
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
CVE-2020-13762 1 Joomla 1 Joomla\! 2020-06-03 6.1 Medium
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
CVE-2020-11890 1 Joomla 1 Joomla\! 2020-04-29 5.3 Medium
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
CVE-2020-10238 1 Joomla 1 Joomla\! 2020-03-19 7.5 High
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.