Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9711 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS. | ||
| CVE-2019-7744 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability. | ||
| CVE-2019-7742 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector. | ||
| CVE-2019-7741 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS. | ||
| CVE-2019-7740 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector. | ||
| CVE-2019-7739 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain… | ||
| CVE-2019-6264 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability. | ||
| CVE-2019-6261 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability. | ||
| CVE-2018-12711 | Med | 0.40 | 6.1 | 0.02 | Jun 26, 2018 | An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or… | ||
| CVE-2018-6378 | Med | 0.40 | 6.1 | 0.02 | May 22, 2018 | In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager. | ||
| CVE-2018-6380 | Med | 0.40 | 6.1 | 0.02 | Jan 30, 2018 | In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. | ||
| CVE-2018-6379 | Med | 0.40 | 6.1 | 0.02 | Jan 30, 2018 | In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability. | ||
| CVE-2015-5608 | Med | 0.40 | 6.1 | 0.01 | Sep 20, 2017 | Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1. | ||
| CVE-2017-11612 | Med | 0.40 | 6.1 | 0.01 | Jul 26, 2017 | In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components. | ||
| CVE-2017-9934 | Med | 0.40 | 6.1 | 0.03 | Jul 17, 2017 | Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability. | ||
| CVE-2017-7987 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component. | ||
| CVE-2017-7986 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components. | ||
| CVE-2017-7985 | Med | 0.40 | 6.1 | 0.02 | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components. | ||
| CVE-2017-7984 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. | ||
| CVE-2018-11324 | Med | 0.38 | 5.9 | 0.01 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated. |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.
- risk 0.40cvss 6.1epss 0.02
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or…
- risk 0.40cvss 6.1epss 0.02
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
- risk 0.40cvss 6.1epss 0.02
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
- risk 0.40cvss 6.1epss 0.02
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
- risk 0.40cvss 6.1epss 0.01
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.03
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.02
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.
Page 9 of 21