VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2010-2923Jul 30, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.

  • CVE-2010-2921Jul 30, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php.

  • CVE-2010-2919Jul 30, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2010-2908Jul 28, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php.

  • CVE-2010-2907Jul 28, 2010
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php.

  • CVE-2010-2857Jul 25, 2010
    risk 0.03cvss —epss 0.05

    Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.

  • CVE-2010-2848Jul 25, 2010
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.

  • CVE-2010-2847Jul 25, 2010
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allow remote attackers to execute arbitrary SQL commands via the viewform parameter in a (1) ferforms or (2) tferforms action to index.php, and the (3) id…

  • CVE-2010-2846Jul 25, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the afmsg parameter to index.php.

  • CVE-2010-2845Jul 25, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the QuickFAQ (com_quickfaq) component 1.0.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a category action to index.php.

  • CVE-2010-2681Jul 12, 2010
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig.absolute.path parameter to index.php.

  • CVE-2010-2679Jul 8, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

  • CVE-2010-2613Jul 2, 2010
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song review field, which is not properly handled in a view action to index.php.

  • CVE-2010-2255Jun 9, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid…

  • CVE-2010-2148Jun 3, 2010
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php.

  • CVE-2010-2129Jun 1, 2010
    risk 0.03cvss —epss 0.05

    Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from…

  • CVE-2010-2044May 25, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.

  • CVE-2010-1950May 19, 2010
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this…

  • CVE-2010-1949May 19, 2010
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2010-1877May 12, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.

  • CVE-2010-1874May 12, 2010
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third…

  • CVE-2010-1873May 12, 2010
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third…

  • CVE-2010-1746May 6, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php.

  • CVE-2010-1739May 6, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.

  • CVE-2010-1721May 4, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.

  • CVE-2010-1720May 4, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php.

  • CVE-2010-1716May 4, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

  • CVE-2010-1600Apr 29, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.

  • CVE-2010-1559Apr 27, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third…

  • CVE-2010-1529Apr 26, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php.

  • CVE-2010-1496Apr 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php.

  • CVE-2010-1493Apr 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php.

  • CVE-2009-4789Apr 21, 2010
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php.

  • CVE-2009-4784Apr 21, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php.

  • CVE-2010-1477Apr 19, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php.

  • CVE-2010-1468Apr 19, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Multi-Venue Restaurant Menu Manager (aka MVRMM or com_mv_restaurantmenumanager) component 1.5.2 Stable Update 3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the mid parameter in a menu_display action to…

  • CVE-2010-1372Apr 13, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2010-1363Apr 13, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.

  • CVE-2010-1350Apr 12, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

  • CVE-2010-1344Apr 9, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter in a detail action to index.php.

  • CVE-2010-1265Apr 6, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2010-1073Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.

  • CVE-2010-1045Mar 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2010-0981Mar 16, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.

  • CVE-2010-0945Mar 8, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2010-0803Mar 2, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the jVideoDirect (com_jvideodirect) component 1.1 RC3b for Joomla! allows remote attackers to execute arbitrary SQL commands via the v parameter to index.php.

  • CVE-2010-0801Mar 2, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory traversal sequences in the controller parameter in an edit task…

  • CVE-2010-0800Mar 2, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a view_category action to index.php.

  • CVE-2010-0796Mar 2, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the eid parameter in a question action to index.php.

  • CVE-2010-0795Mar 2, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an event action to index.php.

Page 16 of 26