VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2014-4960Jul 21, 2014
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

  • CVE-2014-0794Jan 26, 2014
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a comment.like action to index.php.

  • CVE-2013-3242May 3, 2013
    risk 0.03cvss —epss 0.05

    plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via…

  • CVE-2013-1453Feb 13, 2013
    risk 0.03cvss —epss 0.03

    plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete arbitrary directories, conduct SQL injection attacks, and possibly have other impacts via…

  • CVE-2010-5280Nov 26, 2012
    risk 0.03cvss —epss 0.05

    Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to…

  • CVE-2011-4909Oct 7, 2012
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3)…

  • CVE-2006-7247Sep 6, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

  • CVE-2011-5148Aug 31, 2012
    risk 0.03cvss —epss 0.05

    Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then…

  • CVE-2011-5113Aug 23, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in frontend/models/techfoliodetail.php in Techfolio (com_techfolio) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

  • CVE-2011-5112Aug 23, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Alameda (com_alameda) component before 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the storeid parameter to index.php.

  • CVE-2011-4823Dec 15, 2011
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.

  • CVE-2011-4808Dec 14, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php.

  • CVE-2011-4571Nov 29, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php.

  • CVE-2011-4570Nov 29, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns action to index.php.

  • CVE-2010-5056Nov 23, 2011
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.

  • CVE-2010-5044Nov 2, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. …

  • CVE-2010-5043Nov 2, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.

  • CVE-2010-5032Nov 2, 2011
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.

  • CVE-2010-4971Nov 2, 2011
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.

  • CVE-2010-5003Nov 1, 2011
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party…

  • CVE-2010-4995Nov 1, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.

  • CVE-2010-4993Nov 1, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the eventcal (com_eventcal) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

  • CVE-2010-4992Nov 1, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html.

  • CVE-2010-4991Nov 1, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php.

  • CVE-2010-4990Nov 1, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.

  • CVE-2010-4949Oct 9, 2011
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window.

  • CVE-2010-4945Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the CamelcityDB (com_camelcitydb2) component 2.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2010-4944Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php.

  • CVE-2010-4941Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Teams (com_teams) component 1_1028_100809_1711 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PlayerID parameter in a player save action to index.php.

  • CVE-2010-4938Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to index.php. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2010-4937Oct 9, 2011
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the Amblog (com_amblog) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) articleid or (2) catid parameter to index.php.

  • CVE-2010-4929Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the firstCode parameter in a helpers action to index.php.

  • CVE-2010-4928Oct 9, 2011
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML by placing it after a > (greater than) character.

  • CVE-2010-4927Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a country action to index.php.

  • CVE-2010-4926Oct 9, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.

  • CVE-2010-4904Oct 8, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_name parameter in a view action to index.php. NOTE: some of these details are obtained from third party…

  • CVE-2010-4902Oct 8, 2011
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.

  • CVE-2010-4864Oct 5, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.

  • CVE-2010-4853Oct 5, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php.

  • CVE-2010-4837Sep 14, 2011
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are…

  • CVE-2010-4795Apr 27, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. NOTE: some of these details are obtained from third party…

  • CVE-2011-0511Jan 20, 2011
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2011-0504Jan 20, 2011
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote attackers to inject arbitrary web script or HTML via the (1) status parameter to admin/orders.php, (2) search parameter to admin/customers.php, or (3) STORE_NAME…

  • CVE-2011-0503Jan 20, 2011
    risk 0.03cvss —epss 0.02

    Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via…

  • CVE-2011-0005Jan 11, 2011
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.

  • CVE-2010-4638Dec 30, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the submitSurvey function in controller.php in JQuarks4s (com_jquarks4s) component 1.0.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the q parameter in a submitSurvey action to…

  • CVE-2010-4365Dec 1, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php.

  • CVE-2010-4268Nov 17, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Pulse Infotech Flip Wall (com_flipwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2010-3422Sep 16, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

  • CVE-2010-3211Sep 3, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operations with (1) the catid parameter or (2) the catid parameter in a lists action.

Page 15 of 26