Vendor CVEs
Joomla
All CVEs
1,291 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-5974 | Cri | 0.67 | 9.8 | 0.02 | Feb 17, 2018 | SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. | ||
| CVE-2018-5971 | Cri | 0.67 | 9.8 | 0.02 | Feb 17, 2018 | SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter. | ||
| CVE-2018-5970 | Cri | 0.67 | 9.8 | 0.02 | Feb 17, 2018 | SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter. | ||
| CVE-2018-6609 | Cri | 0.67 | 9.8 | 0.02 | Feb 5, 2018 | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action. | ||
| CVE-2018-6581 | Cri | 0.67 | 9.8 | 0.02 | Feb 2, 2018 | SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter. | ||
| CVE-2018-6579 | Cri | 0.67 | 9.8 | 0.03 | Feb 2, 2018 | SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. | ||
| CVE-2018-6575 | Cri | 0.67 | 9.8 | 0.02 | Feb 2, 2018 | SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. | ||
| CVE-2018-6398 | Cri | 0.67 | 9.8 | 0.02 | Jan 30, 2018 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | ||
| CVE-2018-6395 | Cri | 0.67 | 9.8 | 0.02 | Jan 30, 2018 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | ||
| CVE-2018-5984 | Cri | 0.67 | 9.8 | 0.02 | Jan 24, 2018 | SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI. | ||
| CVE-2017-17870 | Cri | 0.67 | 9.8 | 0.02 | Dec 27, 2017 | The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. | ||
| CVE-2017-15966 | Cri | 0.67 | 9.8 | 0.03 | Oct 29, 2017 | The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. | ||
| CVE-2017-15965 | Cri | 0.67 | 9.8 | 0.03 | Oct 29, 2017 | The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | ||
| CVE-2015-4073 | Cri | 0.67 | 9.8 | 0.03 | Sep 20, 2017 | Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the… | ||
| CVE-2015-2798 | Cri | 0.67 | 9.8 | 0.03 | Jul 25, 2017 | SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||
| CVE-2020-35613 | Cri | 0.66 | 9.8 | 0.29 | Dec 28, 2020 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list. | ||
| CVE-2026-76607 | Cri | 0.65 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. | ||
| CVE-2026-76606 | Cri | 0.65 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2. | ||
| CVE-2026-75949 | Cri | 0.65 | — | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak… | ||
| CVE-2026-67364 | Cri | 0.65 | — | 0.00 | Aug 19, 2026 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X]… | ||
| CVE-2026-67282 | Cri | 0.65 | — | 0.01 | Aug 12, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model. | ||
| CVE-2026-66915 | Cri | 0.65 | — | 0.01 | Aug 10, 2026 | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin. | ||
| CVE-2026-73373 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. | ||
| CVE-2026-65887 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins. | ||
| CVE-2026-65890 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | ||
| CVE-2026-65884 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions. | ||
| CVE-2026-48904 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | ||
| CVE-2026-48902 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | ||
| CVE-2026-48899 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. | ||
| CVE-2026-48898 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. | ||
| CVE-2026-40383 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. | ||
| CVE-2026-35223 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. | ||
| CVE-2026-35222 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | ||
| CVE-2026-35221 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2026 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | ||
| CVE-2026-34424 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2026 | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote… | ||
| CVE-2025-26855 | Cri | 0.64 | 9.8 | 0.00 | Jul 18, 2025 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands. | ||
| CVE-2025-26854 | Cri | 0.64 | 9.8 | 0.00 | Jul 18, 2025 | A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands. | ||
| CVE-2025-25226 | Cri | 0.64 | 9.8 | 0.00 | Apr 8, 2025 | Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the… | ||
| CVE-2025-22204 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2025 | Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. | ||
| CVE-2024-40744 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2024 | Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. | ||
| CVE-2023-49708 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQLi vulnerability in Starshop component for Joomla. | ||
| CVE-2023-49707 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQLi vulnerability in S5 Register module for Joomla. | ||
| CVE-2023-40630 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | Unauthenticated LFI/SSRF in JCDashboards component for Joomla. | ||
| CVE-2023-40629 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQLi vulnerability in LMS Lite component for Joomla. | ||
| CVE-2023-39970 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution. | ||
| CVE-2023-38044 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-34477 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-34476 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-23758 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-23757 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. |
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
- risk 0.67cvss 9.8epss 0.03
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.
- risk 0.67cvss 9.8epss 0.02
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
- risk 0.67cvss 9.8epss 0.03
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.
- risk 0.67cvss 9.8epss 0.03
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.
- risk 0.67cvss 9.8epss 0.03
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the…
- risk 0.67cvss 9.8epss 0.03
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- risk 0.66cvss 9.8epss 0.29
An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
- risk 0.65cvss —epss 0.00
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
- risk 0.65cvss —epss 0.00
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
- risk 0.65cvss —epss 0.00
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…
- risk 0.65cvss —epss 0.00
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X]…
- risk 0.65cvss —epss 0.01
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.
- risk 0.65cvss —epss 0.01
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
- risk 0.64cvss 9.8epss 0.00
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
- risk 0.64cvss 9.8epss 0.00
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
- risk 0.64cvss 9.8epss 0.00
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
- risk 0.64cvss 9.8epss 0.00
An improper access check allows privilege escalation through the com_users batch task.
- risk 0.64cvss 9.8epss 0.00
An improper access check allows privilege escalation through the com_users batch task.
- risk 0.64cvss 9.8epss 0.01
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
- risk 0.64cvss 9.8epss 0.00
An improper access check allows unauthorized access to com_config webservice endpoints.
- risk 0.64cvss 9.8epss 0.00
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
- risk 0.64cvss 9.8epss 0.00
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
- risk 0.64cvss 9.8epss 0.01
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote…
- risk 0.64cvss 9.8epss 0.00
A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.00
A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.00
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the…
- risk 0.64cvss 9.8epss 0.01
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
- risk 0.64cvss 9.8epss 0.01
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
- risk 0.64cvss 9.8epss 0.01
SQLi vulnerability in Starshop component for Joomla.
- risk 0.64cvss 9.8epss 0.01
SQLi vulnerability in S5 Register module for Joomla.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
- risk 0.64cvss 9.8epss 0.01
SQLi vulnerability in LMS Lite component for Joomla.
- risk 0.64cvss 9.8epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
Page 2 of 26