VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2007-4503Aug 23, 2007
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid parameter.

  • CVE-2007-4509Aug 23, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did parameter in a details action.

  • CVE-2007-4502Aug 23, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

  • CVE-2007-4186Aug 8, 2007
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2007-4046Jul 27, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

  • CVE-2007-3249Jun 18, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter.

  • CVE-2007-3130Jun 8, 2007
    risk 0.03cvss —epss 0.04

    Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2)…

  • CVE-2007-2933May 31, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.

  • CVE-2007-2792May 22, 2007
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained…

  • CVE-2007-2319Apr 26, 2007
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.

  • CVE-2007-2143Apr 19, 2007
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2007-2089Apr 18, 2007
    risk 0.03cvss —epss 0.06

    Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2)…

  • CVE-2007-1704Mar 27, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-1703Mar 27, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

  • CVE-2006-6962Jan 29, 2007
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. NOTE: this issue may overlap CVE-2006-5047.

  • CVE-2006-6051Nov 22, 2006
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-5096Sep 29, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid parameter in a (1)…

  • CVE-2006-5044Sep 27, 2006
    risk 0.03cvss —epss 0.02

    Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.

  • CVE-2006-5043Sep 27, 2006
    risk 0.03cvss —epss 0.04

    Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload.php, a variant of…

  • CVE-2006-5045Sep 27, 2006
    risk 0.03cvss —epss 0.06

    Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php.

  • CVE-2006-4553Sep 6, 2006
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-4348Aug 24, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-4242Aug 21, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-4129Aug 14, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter.

  • CVE-2006-4074Aug 11, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-3969Aug 1, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-3774Jul 24, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-3750Jul 21, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-3530Jul 12, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_absolute_path…

  • CVE-2026-49049HigJun 29, 2026
    risk 0.01cvss 7.5epss 0.01

    The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

  • CVE-2007-4187Aug 8, 2007
    risk 0.01cvss —epss 0.11

    Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1)…

  • CVE-2007-0373Jan 19, 2007
    risk 0.01cvss —epss 0.12

    Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter…

  • CVE-2026-73327Aug 12, 2026
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified…

  • CVE-2026-65882MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.

  • CVE-2026-65881HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.

  • CVE-2026-65879CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

  • CVE-2026-65878HigJul 27, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

  • CVE-2026-65877HigJul 27, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

  • CVE-2026-65766CriJul 27, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

  • CVE-2026-65761CriJul 23, 2026
    risk 0.00cvss —epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

  • CVE-2026-65760CriJul 23, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

  • CVE-2026-65759HigJul 23, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order…

  • CVE-2026-65758HigJul 23, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

  • CVE-2026-65757HigJul 23, 2026
    risk 0.00cvss 8.1epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.

  • CVE-2026-65756MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

  • CVE-2026-65755HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries,…

  • CVE-2026-65754HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

  • CVE-2026-65713MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

  • CVE-2026-65712MedJul 23, 2026
    risk 0.00cvss 6.2epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.

  • CVE-2026-65431CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

Page 21 of 26