VYPR

Joomla!

by Joomla

Source repositories

CVEs (418)

  • CVE-2022-23798MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.

  • CVE-2022-23796MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.

  • CVE-2021-26039MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.

  • CVE-2021-26035MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

  • CVE-2021-26032MedMay 26, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.

  • CVE-2021-23130MedMar 4, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.

  • CVE-2021-23129MedMar 4, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.

  • CVE-2021-23125MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.

  • CVE-2020-24599MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.

  • CVE-2020-24598MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

  • CVE-2020-15696MedJul 15, 2020
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.

  • CVE-2020-13762MedJun 2, 2020
    risk 0.40cvss 6.1epss 0.01

    In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.

  • CVE-2020-13761MedJun 2, 2020
    risk 0.40cvss 6.1epss 0.01

    In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.

  • CVE-2020-10242MedMar 16, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.

  • CVE-2020-8421MedJan 28, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.

  • CVE-2019-16725MedSep 24, 2019
    risk 0.40cvss 6.1epss 0.01

    In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.

  • CVE-2019-12766MedJun 11, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.

  • CVE-2019-11809MedMay 20, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.

  • CVE-2019-9714MedMar 12, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.

  • CVE-2019-9712MedMar 12, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.

Page 8 of 21