Vendor CVEs
Joomla
All CVEs
1,291 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-4912 | Med | 0.35 | 5.3 | 0.01 | Feb 4, 2020 | Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. | ||
| CVE-2011-3595 | Med | 0.35 | 5.4 | 0.01 | Jan 22, 2020 | Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. | ||
| CVE-2011-4907 | Med | 0.35 | 5.3 | 0.01 | Jan 15, 2020 | Joomla! 1.5x through 1.5.12: Missing JEXEC Check | ||
| CVE-2019-19845 | Med | 0.35 | 5.3 | 0.01 | Dec 18, 2019 | In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. | ||
| CVE-2019-15120 | Med | 0.35 | 5.4 | 0.01 | Aug 16, 2019 | The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode. | ||
| CVE-2019-15028 | Med | 0.35 | 5.3 | 0.01 | Aug 14, 2019 | In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. | ||
| CVE-2019-9919 | Med | 0.35 | 5.4 | 0.01 | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS. | ||
| CVE-2019-6262 | Med | 0.35 | 5.4 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS. | ||
| CVE-2015-3619 | Med | 0.35 | 5.4 | 0.01 | Feb 6, 2018 | Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company." | ||
| CVE-2013-7431 | Med | 0.35 | 5.3 | 0.01 | Aug 29, 2017 | Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!. | ||
| CVE-2017-8057 | Med | 0.35 | 5.3 | 0.01 | Apr 25, 2017 | In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting. | ||
| CVE-2017-7988 | Med | 0.35 | 5.3 | 0.01 | Apr 25, 2017 | In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. | ||
| CVE-2017-7983 | Med | 0.35 | 5.3 | 0.01 | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. | ||
| CVE-2005-4650 | Med | 0.35 | 5.3 | 0.02 | Dec 31, 2005 | Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots. | ||
| CVE-2026-82191 | Med | 0.34 | — | 0.00 | Sep 15, 2026 | Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes… | ||
| CVE-2026-85196 | Med | 0.34 | — | 0.00 | Sep 14, 2026 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context… | ||
| CVE-2026-78000 | Med | 0.34 | — | 0.00 | Sep 3, 2026 | Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host,… | ||
| CVE-2026-78079 | Med | 0.34 | — | 0.00 | Aug 31, 2026 | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal. | ||
| CVE-2026-77990 | Med | 0.34 | — | 0.00 | Aug 27, 2026 | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to… | ||
| CVE-2026-77989 | Med | 0.34 | — | 0.00 | Aug 27, 2026 | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector. | ||
| CVE-2026-77993 | Med | 0.34 | — | 0.00 | Aug 24, 2026 | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter. | ||
| CVE-2026-67358 | Med | 0.34 | — | 0.00 | Aug 21, 2026 | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also… | ||
| CVE-2026-76569 | Med | 0.34 | — | 0.00 | Aug 20, 2026 | Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | ||
| CVE-2026-76565 | Med | 0.34 | — | 0.00 | Aug 20, 2026 | Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 | ||
| CVE-2026-67366 | Med | 0.34 | — | 0.00 | Aug 14, 2026 | Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check. | ||
| CVE-2026-66489 | Med | 0.34 | 5.3 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 | ||
| CVE-2026-66488 | Med | 0.34 | 5.3 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | ||
| CVE-2018-25327 | Med | 0.34 | 5.3 | 0.00 | May 17, 2026 | Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete… | ||
| CVE-2025-54477 | Med | 0.34 | 5.3 | 0.00 | Sep 30, 2025 | Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. | ||
| CVE-2025-50126 | Med | 0.34 | — | 0.00 | Jul 18, 2025 | A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text] parameter. | ||
| CVE-2023-39974 | Med | 0.34 | 5.3 | 0.01 | Aug 17, 2023 | Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list. | ||
| CVE-2022-27912 | Med | 0.34 | 5.3 | 0.01 | Oct 25, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. | ||
| CVE-2022-27911 | Med | 0.34 | 5.3 | 0.01 | Aug 31, 2022 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. | ||
| CVE-2019-6263 | Med | 0.34 | 4.8 | 0.05 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS. | ||
| CVE-2026-81566 | Med | 0.33 | — | 0.00 | Sep 14, 2026 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the… | ||
| CVE-2026-78076 | Med | 0.33 | — | 0.00 | Aug 31, 2026 | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or… | ||
| CVE-2026-78075 | Med | 0.33 | — | 0.00 | Aug 31, 2026 | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image… | ||
| CVE-2026-77035 | Med | 0.33 | — | 0.00 | Aug 27, 2026 | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their… | ||
| CVE-2026-77997 | Med | 0.33 | — | 0.00 | Aug 25, 2026 | Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules… | ||
| CVE-2026-67362 | Med | 0.33 | — | 0.00 | Aug 21, 2026 | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the… | ||
| CVE-2026-75955 | Med | 0.33 | — | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute. | ||
| CVE-2026-71570 | Med | 0.33 | — | 0.00 | Aug 14, 2026 | Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles. | ||
| CVE-2025-50058 | Med | 0.33 | — | 0.00 | Jul 18, 2025 | A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component. | ||
| CVE-2024-40747 | Med | 0.33 | 6.1 | 0.00 | Jan 7, 2025 | Various module chromes didn't properly process inputs, leading to XSS vectors. | ||
| CVE-2025-22209 | Med | 0.31 | 4.7 | 0.00 | Feb 15, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature. | ||
| CVE-2025-22208 | Med | 0.31 | 4.7 | 0.01 | Feb 15, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature. | ||
| CVE-2025-22206 | Med | 0.31 | 4.7 | 0.10 | Feb 4, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature. | ||
| CVE-2015-7344 | Med | 0.31 | 4.8 | 0.01 | Mar 9, 2020 | HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption]. | ||
| CVE-2018-18276 | Med | 0.31 | 4.8 | 0.01 | Apr 26, 2019 | XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel. | ||
| CVE-2018-11328 | Med | 0.31 | 4.7 | 0.02 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS… |
- risk 0.35cvss 5.3epss 0.01
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
- risk 0.35cvss 5.4epss 0.01
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
- risk 0.35cvss 5.3epss 0.01
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
- risk 0.35cvss 5.3epss 0.01
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
- risk 0.35cvss 5.4epss 0.01
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
- risk 0.35cvss 5.3epss 0.01
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company."
- risk 0.35cvss 5.3epss 0.01
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
- risk 0.35cvss 5.3epss 0.01
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
- risk 0.35cvss 5.3epss 0.01
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
- risk 0.35cvss 5.3epss 0.01
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
- risk 0.35cvss 5.3epss 0.02
Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.
- risk 0.34cvss —epss 0.00
Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes…
- risk 0.34cvss —epss 0.00
Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context…
- risk 0.34cvss —epss 0.00
Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host,…
- risk 0.34cvss —epss 0.00
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.
- risk 0.34cvss —epss 0.00
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to…
- risk 0.34cvss —epss 0.00
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
- risk 0.34cvss —epss 0.00
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.
- risk 0.34cvss —epss 0.00
Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also…
- risk 0.34cvss —epss 0.00
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
- risk 0.34cvss —epss 0.00
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
- risk 0.34cvss —epss 0.00
Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.
- risk 0.34cvss 5.3epss 0.00
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
- risk 0.34cvss 5.3epss 0.00
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
- risk 0.34cvss 5.3epss 0.00
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete…
- risk 0.34cvss 5.3epss 0.00
Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
- risk 0.34cvss —epss 0.00
A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text] parameter.
- risk 0.34cvss 5.3epss 0.01
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.
- risk 0.34cvss 4.8epss 0.05
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.
- risk 0.33cvss —epss 0.00
Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the…
- risk 0.33cvss —epss 0.00
Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or…
- risk 0.33cvss —epss 0.00
Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image…
- risk 0.33cvss —epss 0.00
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their…
- risk 0.33cvss —epss 0.00
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules…
- risk 0.33cvss —epss 0.00
Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the…
- risk 0.33cvss —epss 0.00
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
- risk 0.33cvss —epss 0.00
Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.
- risk 0.33cvss —epss 0.00
A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
- risk 0.33cvss 6.1epss 0.00
Various module chromes didn't properly process inputs, leading to XSS vectors.
- risk 0.31cvss 4.7epss 0.00
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.
- risk 0.31cvss 4.7epss 0.01
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.
- risk 0.31cvss 4.7epss 0.10
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.
- risk 0.31cvss 4.8epss 0.01
HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
- risk 0.31cvss 4.8epss 0.01
XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel.
- risk 0.31cvss 4.7epss 0.02
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS…
Page 11 of 26