VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2009-2607Jul 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php.

  • CVE-2009-2601Jul 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php.

  • CVE-2009-2554Jul 20, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the search method in jobline.class.php in Jobline (com_jobline) 1.1.2.2, 1.3.1, and possibly earlier versions, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the search parameter in a results action to…

  • CVE-2009-2395Jul 9, 2009
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.

  • CVE-2009-2390Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter to index.php.

  • CVE-2008-6852Jul 7, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2008-6841Jul 1, 2009
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to…

  • CVE-2009-2239Jun 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3) casino_videopoker (com_casino_videopoker) components 0.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to…

  • CVE-2009-2102Jun 17, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary SQL commands via the fileid parameter to index.php.

  • CVE-2009-2099Jun 17, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.

  • CVE-2009-2014Jun 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php.

  • CVE-2009-1938Jun 5, 2009
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output and the frontend administrative panel.

  • CVE-2009-1736May 20, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.

  • CVE-2009-1499May 1, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus states that this issue has been disputed by the vendor.

  • CVE-2008-6653Apr 7, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2008-6489Mar 19, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.

  • CVE-2008-6481Mar 17, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

  • CVE-2008-6430Mar 6, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

  • CVE-2008-6429Mar 6, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.

  • CVE-2009-0730Feb 24, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which…

  • CVE-2009-0726Feb 24, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php.

  • CVE-2009-0702Feb 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.

  • CVE-2008-6234Feb 21, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2008-6184Feb 19, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a catalogue action to index.php.

  • CVE-2008-6182Feb 19, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in a view action to index.php.

  • CVE-2008-6166Feb 19, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.

  • CVE-2008-6149Feb 16, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cagtegory parameter in a story_lists action to index.php.

  • CVE-2008-6148Feb 16, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.

  • CVE-2008-6116Feb 11, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php.

  • CVE-2008-6068Feb 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.

  • CVE-2009-0494Feb 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.

  • CVE-2008-6088Feb 6, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.

  • CVE-2008-6076Feb 6, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2009-0421Feb 5, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2009-0420Feb 5, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2008-6050Feb 4, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php.

  • CVE-2009-0381Feb 2, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.

  • CVE-2009-0380Feb 2, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different vector than CVE-2008-0607. …

  • CVE-2009-0379Feb 2, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761.

  • CVE-2009-0378Feb 2, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

  • CVE-2009-0377Feb 2, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.

  • CVE-2009-0373Jan 30, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.

  • CVE-2009-0333Jan 29, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.

  • CVE-2009-0329Jan 29, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.

  • CVE-2008-5957Jan 23, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php.

  • CVE-2008-5811Jan 2, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php.

  • CVE-2008-5643Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter in a book_details action to index.php.

  • CVE-2008-5607Dec 16, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2008-5494Dec 12, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2008-5208Nov 24, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

Page 18 of 26