Bitnami package
joomla
pkg:bitnami/joomla
Vulnerabilities (134)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-23125 | Med | 6.1 | >= 3.1.0, <= 3.9.23 | — | Jan 12, 2021 | An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors. | |
| CVE-2021-23124 | Med | 6.1 | >= 3.9.0, <= 3.9.23 | — | Jan 12, 2021 | An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks. | |
| CVE-2021-23123 | Med | 5.3 | >= 3.0.0, <= 3.9.23 | — | Jan 12, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules. | |
| CVE-2020-35616 | Hig | 7.5 | >= 1.7.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. | |
| CVE-2020-35615 | Med | 6.3 | >= 2.5.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability. | |
| CVE-2020-35614 | Med | 5.3 | >= 3.9.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page. | |
| CVE-2020-35613 | Cri | 9.8 | >= 3.0.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list. | |
| CVE-2020-35612 | Hig | 7.5 | >= 2.5.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability. | |
| CVE-2020-35611 | Hig | 7.5 | >= 2.5.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values. | |
| CVE-2020-35610 | Hig | 7.5 | >= 2.5.0, <= 3.9.22 | — | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms. | |
| CVE-2020-24599 | Med | 6.1 | >= 3.9.0, < 3.9.21 | 3.9.21 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. | |
| CVE-2020-24598 | Med | 6.1 | >= 3.0.0, < 3.9.21 | 3.9.21 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. | |
| CVE-2020-15700 | Med | 6.3 | >= 3.7.0, <= 3.9.19 | — | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. | |
| CVE-2020-15699 | Med | 5.3 | >= 2.5.0, <= 3.9.19 | — | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. | |
| CVE-2020-15698 | Med | 5.3 | >= 3.0.0, <= 3.9.19 | — | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials | |
| CVE-2020-15697 | Med | 4.3 | >= 3.0.0, <= 3.9.19 | — | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users. | |
| CVE-2020-15696 | Med | 6.1 | >= 3.0.0, <= 3.9.19 | — | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. | |
| CVE-2020-15695 | Med | 6.3 | >= 3.9.0, <= 3.9.19 | — | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. | |
| CVE-2020-13763 | Hig | 7.5 | >= 2.5.0, < 3.9.19 | 3.9.19 | Jun 2, 2020 | In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users. | |
| CVE-2020-13762 | Med | 6.1 | >= 3.9.0, < 3.9.19 | 3.9.19 | Jun 2, 2020 | In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. |
- affected >= 3.1.0, <= 3.9.23
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
- affected >= 3.9.0, <= 3.9.23
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
- affected >= 3.0.0, <= 3.9.23
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
- affected >= 1.7.0, <= 3.9.22
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.
- affected >= 2.5.0, <= 3.9.22
An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
- affected >= 3.9.0, <= 3.9.22
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
- affected >= 3.0.0, <= 3.9.22
An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
- affected >= 2.5.0, <= 3.9.22
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
- affected >= 2.5.0, <= 3.9.22
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
- affected >= 2.5.0, <= 3.9.22
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
- affected >= 3.9.0, < 3.9.21fixed 3.9.21
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
- affected >= 3.0.0, < 3.9.21fixed 3.9.21
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
- affected >= 3.7.0, <= 3.9.19
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
- affected >= 2.5.0, <= 3.9.19
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
- affected >= 3.0.0, <= 3.9.19
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
- affected >= 3.0.0, <= 3.9.19
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
- affected >= 3.0.0, <= 3.9.19
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
- affected >= 3.9.0, <= 3.9.19
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
- affected >= 2.5.0, < 3.9.19fixed 3.9.19
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
- affected >= 3.9.0, < 3.9.19fixed 3.9.19
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
Page 6 of 7