Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2006-4129

Published Aug 14, 2006

PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary P…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4074

Published Aug 11, 2006

PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3969

Published Aug 1, 2006

PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3970

Published Aug 1, 2006

PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3774

Published Jul 24, 2006

PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3530

Published Jul 12, 2006

PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is en…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3480

Published Jul 10, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3481

Published Jul 10, 2006

Multiple SQL injection vulnerabilities in Joomla! before 1.0.10 allow remote attackers to execute arbitrary SQL commands via unspecified parameters involving the (1) "Remember Me"…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2960

Published Jun 12, 2006

PHP remote file inclusion vulnerability in includes/joomla.php in Joomla! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1956

Published Apr 21, 2006

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1957

Published Apr 21, 2006

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple reque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1047

Published Mar 7, 2006

Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-1048

Published Mar 7, 2006

Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1049

Published Mar 7, 2006

Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via unkn…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1027

Published Mar 7, 2006

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via a "/" (slash) in the feed parameter to index.php…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1028

Published Mar 7, 2006

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filena…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1029

Published Mar 7, 2006

The cross-site scripting (XSS) countermeasures in class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause a denial of service via a crafted mosmsg parameter to inde…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1030

Published Mar 7, 2006

Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack vector that reveals the path.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0303

Published Jan 19, 2006

Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unk…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-0114

Published Jan 9, 2006

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4650

Published Dec 31, 2005

Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3771

Published Nov 23, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) "GET and other variables" and (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3772

Published Nov 23, 2005

Multiple SQL injection vulnerabilities in Joomla! before 1.0.4 allow remote attackers to execute arbitrary SQL commands via the (1) Itemid variable in the Polls modules and (2) mu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3773

Published Nov 23, 2005

Unspecified vulnerability in Joomla! before 1.0.4 has unknown impact and attack vectors, related to "Potential misuse of Media component file management functions."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 951-974 of 974 CVEsPage 39 of 39