Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23798 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. | ||
| CVE-2022-23796 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields. | ||
| CVE-2021-26039 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability. | ||
| CVE-2021-26035 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability. | ||
| CVE-2021-26032 | Med | 0.40 | 6.1 | 0.01 | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors. | ||
| CVE-2021-23130 | Med | 0.40 | 6.1 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. | ||
| CVE-2021-23129 | Med | 0.40 | 6.1 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues. | ||
| CVE-2021-23125 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors. | ||
| CVE-2020-24599 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. | ||
| CVE-2020-24598 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. | ||
| CVE-2020-15696 | Med | 0.40 | 6.1 | 0.03 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. | ||
| CVE-2020-13762 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2020 | In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. | ||
| CVE-2020-13761 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2020 | In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS. | ||
| CVE-2020-10242 | Med | 0.40 | 6.1 | 0.01 | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks. | ||
| CVE-2020-8421 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs. | ||
| CVE-2019-16725 | Med | 0.40 | 6.1 | 0.01 | Sep 24, 2019 | In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. | ||
| CVE-2019-12766 | Med | 0.40 | 6.1 | 0.01 | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors. | ||
| CVE-2019-11809 | Med | 0.40 | 6.1 | 0.01 | May 20, 2019 | An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector. | ||
| CVE-2019-9714 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS. | ||
| CVE-2019-9712 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS. |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
- risk 0.40cvss 6.1epss 0.03
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
- risk 0.40cvss 6.1epss 0.01
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
- risk 0.40cvss 6.1epss 0.01
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
Page 8 of 21