Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2006-5043

Published Sep 27, 2006

Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5046

Published Sep 27, 2006

Unspecified vulnerability in RS Gallery2 (com_rsgallery2) 1.11.3 and earlier for Joomla! has unspecified impact and attack vectors, related to lack of "hardened language files."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5047

Published Sep 27, 2006

Unspecified vulnerability in rsgallery2.html.php in RS Gallery2 component (com_rsgallery2) before 1.11.3 for Joomla! allows attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4992

Published Sep 26, 2006

Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosCon…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4995

Published Sep 26, 2006

PHP remote file inclusion vulnerability in BSQ Sitestats (bsq_sitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4996

Published Sep 26, 2006

Unspecified vulnerability in JoomlaLib (com_joomlalib) before 1.2.2 for Joomla! allows remote attackers to have an unknown impact, related to "Joomla globals hacked by script kidd…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4556

Published Sep 6, 2006

PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_ab…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4466

Published Aug 31, 2006

Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4468

Published Aug 31, 2006

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4469

Published Aug 31, 2006

Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4470

Published Aug 31, 2006

Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4471

Published Aug 31, 2006

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4472

Published Aug 31, 2006

Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4473

Published Aug 31, 2006

Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4474

Published Aug 31, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4475

Published Aug 31, 2006

Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4476

Published Aug 31, 2006

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4378

Published Aug 26, 2006

Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4269

Published Aug 21, 2006

PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4242

Published Aug 21, 2006

PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 926-950 of 974 CVEsPage 38 of 39