VYPR

Joomla!

by Joomla

Source repositories

CVEs (418)

  • CVE-2022-23799CriMar 30, 2022
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

  • CVE-2020-13760HigJun 2, 2020
    risk 0.57cvss 8.8epss 0.01

    In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

  • CVE-2020-10241HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

  • CVE-2020-10239HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

  • CVE-2020-8420HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

  • CVE-2020-8419HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

  • CVE-2019-18650HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

  • CVE-2019-14654HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.02

    In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.

  • CVE-2019-11831CriMay 9, 2019
    risk 0.57cvss 9.8epss 0.05

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

  • CVE-2018-17858HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

  • CVE-2018-17855HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.

  • CVE-2018-15882CriAug 29, 2018
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.

  • CVE-2018-12712HigJun 26, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.

  • CVE-2018-11323HigMay 22, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.

  • CVE-2017-11364HigAug 2, 2017
    risk 0.57cvss 8.8epss 0.02

    The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.

  • CVE-2026-71573HigAug 18, 2026
    risk 0.54cvss 8.3epss 0.00

    Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

  • CVE-2016-9838HigDec 16, 2016
    risk 0.53cvss 7.5epss 0.12

    An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's account and reset the user's group…

  • CVE-2012-1563HigJan 15, 2020
    risk 0.52cvss 7.5epss 0.09

    Joomla! before 2.5.3 allows Admin Account Creation.

  • CVE-2026-23899HigApr 1, 2026
    risk 0.50cvss 8.8epss 0.00

    An improper access check allows unauthorized access to webservice endpoints.

  • CVE-2026-21630HigApr 1, 2026
    risk 0.50cvss 8.8epss 0.00

    Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

Page 3 of 21