Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2007-1699

Published Mar 27, 2007

Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1703

Published Mar 27, 2007

SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1704

Published Mar 27, 2007

SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1596

Published Mar 22, 2007

Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PH…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-7122

Published Mar 6, 2007

Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows rem…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7123

Published Mar 6, 2007

Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL com…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7124

Published Mar 6, 2007

PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7125

Published Mar 6, 2007

Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7126

Published Mar 6, 2007

SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7008

Published Feb 12, 2007

Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps C…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7009

Published Feb 12, 2007

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7010

Published Feb 12, 2007

The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6962

Published Jan 29, 2007

PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0373

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0374

Published Jan 19, 2007

SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0375

Published Jan 19, 2007

Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0387

Published Jan 19, 2007

SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6832

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6833

Published Dec 31, 2006

com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6834

Published Dec 31, 2006

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6843

Published Dec 31, 2006

PHP remote file inclusion vulnerability in the BE IT EasyPartner 0.0.9 beta component for Joomla! allows remote attackers to execute arbitrary PHP code via unspecified vectors. N…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 901-925 of 974 CVEsPage 37 of 39