VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2018-5974CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.

  • CVE-2018-5971CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.

  • CVE-2018-5970CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter.

  • CVE-2018-6609CriFeb 5, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.

  • CVE-2018-6581CriFeb 2, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.

  • CVE-2018-6579CriFeb 2, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

  • CVE-2018-6575CriFeb 2, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.

  • CVE-2018-6398CriJan 30, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.

  • CVE-2018-6395CriJan 30, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.

  • CVE-2018-5984CriJan 24, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.

  • CVE-2017-17870CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.02

    The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

  • CVE-2017-15966CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.

  • CVE-2017-15965CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

  • CVE-2015-4073CriSep 20, 2017
    risk 0.67cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the…

  • CVE-2015-2798CriJul 25, 2017
    risk 0.67cvss 9.8epss 0.03

    SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2020-35613CriDec 28, 2020
    risk 0.66cvss 9.8epss 0.29

    An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.

  • CVE-2026-76607CriAug 22, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.

  • CVE-2026-76606CriAug 22, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

  • CVE-2026-75949CriAug 19, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…

  • CVE-2026-67364CriAug 19, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X]…

  • CVE-2026-67282CriAug 12, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

  • CVE-2026-66915CriAug 10, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

  • CVE-2026-73373CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

  • CVE-2026-65887CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

  • CVE-2026-65890CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

  • CVE-2026-65884CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.

  • CVE-2026-48904CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

  • CVE-2026-48902CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

  • CVE-2026-48899CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper access check allows privilege escalation through the com_users batch task.

  • CVE-2026-48898CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper access check allows privilege escalation through the com_users batch task.

  • CVE-2026-40383CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.01

    An improper validation of user-supplied input leads to a local file inclusion vulnerability.

  • CVE-2026-35223CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper access check allows unauthorized access to com_config webservice endpoints.

  • CVE-2026-35222CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

  • CVE-2026-35221CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

  • CVE-2026-34424CriApr 9, 2026
    risk 0.64cvss 9.8epss 0.01

    Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote…

  • CVE-2025-26855CriJul 18, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

  • CVE-2025-26854CriJul 18, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

  • CVE-2025-25226CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the…

  • CVE-2025-22204CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

  • CVE-2024-40744CriDec 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.

  • CVE-2023-49708CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in Starshop component for Joomla.

  • CVE-2023-49707CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in S5 Register module for Joomla.

  • CVE-2023-40630CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated LFI/SSRF in JCDashboards component for Joomla.

  • CVE-2023-40629CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in LMS Lite component for Joomla.

  • CVE-2023-39970CriAug 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

  • CVE-2023-38044CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-34477CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-34476CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-23758CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-23757CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Page 2 of 26