Filtered by vendor Joomla
Subscriptions
Filtered by product Joomla\!
Subscriptions
Total
583 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-10240 | 1 Joomla | 1 Joomla\! | 2020-03-19 | 5.3 Medium |
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses. | ||||
CVE-2020-10242 | 1 Joomla | 1 Joomla\! | 2020-03-18 | 6.1 Medium |
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks. | ||||
CVE-2020-10241 | 1 Joomla | 1 Joomla\! | 2020-03-18 | 8.8 High |
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF. | ||||
CVE-2020-10243 | 1 Joomla | 1 Joomla\! | 2020-03-18 | 9.8 Critical |
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype. | ||||
CVE-2012-2747 | 1 Joomla | 1 Joomla\! | 2020-02-25 | N/A |
Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking." | ||||
CVE-2011-1151 | 1 Joomla | 1 Joomla\! | 2020-02-07 | 9.1 Critical |
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. | ||||
CVE-2020-8420 | 1 Joomla | 1 Joomla\! | 2020-02-07 | 8.8 High |
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability. | ||||
CVE-2020-8419 | 1 Joomla | 1 Joomla\! | 2020-02-06 | 8.8 High |
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities. | ||||
CVE-2020-8421 | 1 Joomla | 1 Joomla\! | 2020-02-06 | 6.1 Medium |
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs. | ||||
CVE-2011-4912 | 1 Joomla | 1 Joomla\! | 2020-02-05 | 5.3 Medium |
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. | ||||
CVE-2011-4937 | 1 Joomla | 1 Joomla\! | 2020-02-05 | 7.5 High |
Joomla! 1.7.1 has core information disclosure due to inadequate error checking. | ||||
CVE-2011-3629 | 1 Joomla | 1 Joomla\! | 2020-02-05 | 7.5 High |
Joomla! core 1.7.1 allows information disclosure due to weak encryption | ||||
CVE-2011-3595 | 1 Joomla | 1 Joomla\! | 2020-01-24 | 5.4 Medium |
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. | ||||
CVE-2011-4907 | 1 Joomla | 1 Joomla\! | 2020-01-22 | 5.3 Medium |
Joomla! 1.5x through 1.5.12: Missing JEXEC Check | ||||
CVE-2012-1563 | 1 Joomla | 1 Joomla\! | 2020-01-22 | 7.5 High |
Joomla! before 2.5.3 allows Admin Account Creation. | ||||
CVE-2012-1562 | 1 Joomla | 1 Joomla\! | 2020-01-22 | 7.5 High |
Joomla! core before 2.5.3 allows unauthorized password change. | ||||
CVE-2019-19845 | 1 Joomla | 1 Joomla\! | 2019-12-19 | 5.3 Medium |
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. | ||||
CVE-2019-19846 | 1 Joomla | 1 Joomla\! | 2019-12-18 | 9.8 Critical |
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. | ||||
CVE-2019-18674 | 1 Joomla | 1 Joomla\! | 2019-11-06 | 5.3 Medium |
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure. | ||||
CVE-2019-18650 | 1 Joomla | 1 Joomla\! | 2019-11-06 | 8.8 High |
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. |