VYPR

Joomla!

by Joomla

Source repositories

CVEs (408)

  • CVE-2022-23799CriMar 30, 2022
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

  • CVE-2020-13760HigJun 2, 2020
    risk 0.57cvss 8.8epss 0.01

    In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

  • CVE-2020-10241HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

  • CVE-2020-10239HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

  • CVE-2020-8420HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

  • CVE-2020-8419HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

  • CVE-2019-18650HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

  • CVE-2019-14654HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.02

    In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.

  • CVE-2018-17858HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

  • CVE-2018-17855HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.

  • CVE-2018-15882CriAug 29, 2018
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.

  • CVE-2018-12712HigJun 26, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.

  • CVE-2018-11323HigMay 22, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.

  • CVE-2017-11364HigAug 2, 2017
    risk 0.57cvss 8.8epss 0.02

    The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.

  • CVE-2016-9838HigDec 16, 2016
    risk 0.53cvss 7.5epss 0.14

    An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's account and reset the user's group…

  • CVE-2012-1563HigJan 15, 2020
    risk 0.52cvss 7.5epss 0.09

    Joomla! before 2.5.3 allows Admin Account Creation.

  • CVE-2026-23899HigApr 1, 2026
    risk 0.50cvss 8.8epss 0.00

    An improper access check allows unauthorized access to webservice endpoints.

  • CVE-2026-21630HigApr 1, 2026
    risk 0.50cvss 8.8epss 0.00

    Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

  • CVE-2023-23752MedKEVFeb 16, 2023
    risk 0.50cvss 5.3epss 1.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

  • CVE-2026-48901HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

Page 3 of 21