VYPR

Joomla!

by Joomla

Source repositories

CVEs (418)

  • CVE-2008-2568Jun 6, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a browse action to index.php.

  • CVE-2008-1935Apr 25, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.

  • CVE-2008-0829Feb 19, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task.

  • CVE-2008-0795Feb 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.

  • CVE-2008-0561Feb 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

  • CVE-2008-0517Jan 31, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.

  • CVE-2007-6272Dec 7, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2) the task parameter to the com_search component, or (3) the option parameter in a search…

  • CVE-2007-5427Oct 12, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. NOTE: this might be related to CVE-2007-4189.1.

  • CVE-2007-5410Oct 12, 2007
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

  • CVE-2007-5309Oct 9, 2007
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

  • CVE-2007-5310Oct 9, 2007
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2007-4781Sep 10, 2007
    risk 0.03cvss —epss 0.05

    administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value…

  • CVE-2007-4187Aug 8, 2007
    risk 0.01cvss —epss 0.11

    Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1)…

  • CVE-2007-0373Jan 19, 2007
    risk 0.01cvss —epss 0.12

    Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter…

  • CVE-2026-73327Aug 12, 2026
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified…

  • CVE-2026-48958HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows unauthorized users to create custom fields via webservices endpoints.

  • CVE-2026-48957HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows unauthorized users to access com_privacy datasets.

  • CVE-2026-48956MedJul 7, 2026
    risk 0.00cvss 5.0epss 0.00

    An improper access check allows users to display a list of modules in the frontend.

  • CVE-2026-48955MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.00

    An improper access check allows unauthorized users to access workflow stage and transition information.

  • CVE-2026-48954MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper validation leads to a generic XSS vector in the language override feature.

Page 14 of 21