VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2010-0760Feb 27, 2010
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) file parameter to libraries/jquery/js/ui/jsloader.php and the…

  • CVE-2010-0753Feb 27, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter to ajax/print.php. NOTE: some of these details are obtained from third party information.

  • CVE-2010-0694Feb 23, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php.

  • CVE-2009-4651Feb 22, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors.

  • CVE-2010-0461Jan 28, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php.

  • CVE-2010-0374Jan 21, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.

  • CVE-2010-0373Jan 21, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

  • CVE-2010-0372Jan 21, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php.

  • CVE-2009-4628Jan 18, 2010
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.

  • CVE-2009-4620Jan 18, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

  • CVE-2009-4604Jan 12, 2010
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-4599Jan 12, 2010
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the md parameter in an employer view_company action to index.php or (2) the oi parameter in an employer view_job…

  • CVE-2009-4598Jan 12, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action to index.php.

  • CVE-2009-4583Jan 6, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.php.

  • CVE-2009-4578Jan 6, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.

  • CVE-2009-4576Jan 6, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php.

  • CVE-2009-4550Jan 4, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.php.

  • CVE-2009-4428Dec 28, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showcat action to index.php.

  • CVE-2009-4217Dec 7, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. NOTE: the provenance of this information is unknown; the…

  • CVE-2009-4200Dec 4, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.

  • CVE-2009-4168Dec 2, 2009
    risk 0.03cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags…

  • CVE-2009-3972Nov 18, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.

  • CVE-2009-3971Nov 18, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.

  • CVE-2009-3964Nov 18, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.

  • CVE-2009-3817Oct 28, 2009
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than CVE-2009-2637. NOTE:…

  • CVE-2009-3661Oct 11, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.

  • CVE-2009-3644Oct 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.

  • CVE-2009-3446Sep 28, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.

  • CVE-2009-3443Sep 28, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.

  • CVE-2009-3438Sep 28, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.

  • CVE-2009-3417Sep 25, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.

  • CVE-2009-3335Sep 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

  • CVE-2009-3334Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.

  • CVE-2009-3332Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.

  • CVE-2009-3325Sep 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.

  • CVE-2009-3193Sep 15, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.

  • CVE-2009-3155Sep 10, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.

  • CVE-2008-7169Sep 8, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.

  • CVE-2009-3063Sep 3, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.

  • CVE-2008-7033Aug 24, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than CVE-2008-2568. NOTE: this issue was…

  • CVE-2008-6923Aug 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.

  • CVE-2008-6883Jul 30, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from…

  • CVE-2008-6882Jul 30, 2009
    risk 0.03cvss —epss 0.02

    Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.

  • CVE-2008-6881Jul 30, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php.

  • CVE-2009-2638Jul 28, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.

  • CVE-2009-2637Jul 28, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-2635Jul 28, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-2634Jul 28, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-2633Jul 28, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2009-2609Jul 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the amoCourse (com_amocourse) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.

Page 17 of 26