Bitnami package
joomla
pkg:bitnami/joomla
Vulnerabilities (134)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-40626 | Hig | 7.5 | >= 1.6.0, < 3.10.14 | 3.10.14 | Nov 29, 2023 | The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. | |
| CVE-2023-23755 | Hig | 7.5 | >= 4.2.0, < 4.3.2 | 4.3.2 | May 30, 2023 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods. | |
| CVE-2023-23754 | Med | 6.1 | >= 4.2.0, < 4.3.2 | 4.3.2 | May 30, 2023 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. | |
| CVE-2023-23752 | Med | 5.3 | KEV | >= 4.0.0, < 4.2.8 | 4.2.8 | Feb 16, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2023-23751 | Med | 4.3 | >= 4.0.0, <= 4.2.4 | — | Feb 1, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs. | |
| CVE-2023-23750 | Med | 6.3 | >= 4.0.0, <= 4.2.6 | — | Feb 1, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages. | |
| CVE-2022-27914 | Med | 6.1 | >= 4.0.0, < 4.2.5 | 4.2.5 | Nov 8, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media. | |
| CVE-2022-27913 | Med | 6.1 | >= 4.0.0, <= 4.2.3 | — | Oct 25, 2022 | An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components. | |
| CVE-2022-27912 | Med | 5.3 | >= 4.0.0, <= 4.2.3 | — | Oct 25, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. | |
| CVE-2022-27911 | Med | 5.3 | >= 4.2.0, <= 4.2.0 | — | Aug 31, 2022 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. | |
| CVE-2022-23801 | Med | 6.1 | >= 4.0.0, <= 4.1.0 | — | Mar 30, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media. | |
| CVE-2022-23800 | Med | 6.1 | >= 4.0.0, <= 4.1.0 | — | Mar 30, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. | |
| CVE-2022-23799 | Cri | 9.8 | >= 4.0.0, <= 4.1.0 | — | Mar 30, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data. | |
| CVE-2022-23798 | Med | 6.1 | >= 2.5.0, <= 3.10.6 | — | Mar 30, 2022 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. | |
| CVE-2022-23797 | Cri | 9.8 | >= 3.0.0, <= 3.10.6 | — | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection. | |
| CVE-2022-23796 | Med | 6.1 | >= 3.7.0, <= 3.10.6 | — | Mar 30, 2022 | An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields. | |
| CVE-2022-23795 | Cri | 9.8 | >= 2.5.0, <= 3.10.6 | — | Mar 30, 2022 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover. | |
| CVE-2022-23794 | Med | 5.3 | >= 3.0.0, <= 3.10.6 | — | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application. | |
| CVE-2022-23793 | Hig | 7.5 | >= 3.0.0, <= 3.10.6 | — | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. | |
| CVE-2021-26040 | Cri | 9.1 | >= 4.0.0, <= 4.0.0 | — | Aug 24, 2021 | An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command. |
- affected >= 1.6.0, < 3.10.14fixed 3.10.14
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
- affected >= 4.2.0, < 4.3.2fixed 4.3.2
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
- affected >= 4.2.0, < 4.3.2fixed 4.3.2
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
- affected >= 4.0.0, < 4.2.8fixed 4.2.8
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- affected >= 4.0.0, <= 4.2.4
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
- affected >= 4.0.0, <= 4.2.6
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
- affected >= 4.0.0, < 4.2.5fixed 4.2.5
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
- affected >= 4.0.0, <= 4.2.3
An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
- affected >= 4.0.0, <= 4.2.3
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
- affected >= 4.2.0, <= 4.2.0
An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.
- affected >= 4.0.0, <= 4.1.0
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
- affected >= 4.0.0, <= 4.1.0
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
- affected >= 4.0.0, <= 4.1.0
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.
- affected >= 2.5.0, <= 3.10.6
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
- affected >= 3.0.0, <= 3.10.6
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.
- affected >= 3.7.0, <= 3.10.6
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
- affected >= 2.5.0, <= 3.10.6
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
- affected >= 3.0.0, <= 3.10.6
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
- affected >= 3.0.0, <= 3.10.6
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
- affected >= 4.0.0, <= 4.0.0
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
Page 4 of 7