Skip to main content

Vendor/product archive

joomla / joomla! CVEs

Beta · best-effort

642 CVEs tagged to joomla / joomla!34 Critical, 281 High, 323 Medium, 4 Low, 0 Unrated.

CVE-2017-14596

Published Sep 20, 2017

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-14595

Published Sep 20, 2017

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

CVSS 3.7 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-11364

Published Aug 2, 2017

The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by le…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11612

Published Jul 26, 2017

In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9934

Published Jul 17, 2017

Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9933

Published Jul 17, 2017

Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8917

Published May 17, 2017

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2017-8057

Published Apr 25, 2017

In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7989

Published Apr 25, 2017

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7988

Published Apr 25, 2017

In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7987

Published Apr 25, 2017

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7986

Published Apr 25, 2017

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-7985

Published Apr 25, 2017

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-7984

Published Apr 25, 2017

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7983

Published Apr 25, 2017

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9081

Published Jan 23, 2017

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9838

Published Dec 16, 2016

An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validatio…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-9837

Published Dec 16, 2016

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_cont…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9836

Published Dec 5, 2016

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP conten…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8870

Published Nov 4, 2016

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote…

CVSS 8.1 · High
evidence mentions
6
Buzz score
27.5
Vendor/product tagsBeta · best-effort

CVE-2016-8869

Published Nov 4, 2016

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by levera…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2015-8769

Published Jan 12, 2016

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 642 CVEsPage 9 of 26