VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2026-71571HigAug 14, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

  • CVE-2025-49486HigJul 18, 2025
    risk 0.56cvss —epss 0.00

    A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.

  • CVE-2025-49485HigJul 18, 2025
    risk 0.56cvss —epss 0.00

    A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.

  • CVE-2015-4075HigSep 20, 2017
    risk 0.56cvss 8.1epss 0.07

    The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.

  • CVE-2015-4074HigSep 20, 2017
    risk 0.56cvss 7.5epss 0.27

    Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

  • CVE-2025-54301HigAug 25, 2025
    risk 0.55cvss —epss 0.00

    A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.

  • CVE-2025-54300HigAug 25, 2025
    risk 0.55cvss —epss 0.00

    A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.

  • CVE-2026-71573HigAug 18, 2026
    risk 0.54cvss 8.3epss 0.00

    Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

  • CVE-2020-23972HigAug 27, 2020
    risk 0.54cvss 7.5epss 0.31

    In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file…

  • CVE-2018-10063HigApr 12, 2018
    risk 0.54cvss 7.8epss 0.10

    The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.

  • CVE-2026-66491HigAug 7, 2026
    risk 0.53cvss —epss 0.00

    Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

  • CVE-2019-25756HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with…

  • CVE-2019-25755HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with…

  • CVE-2019-25754HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint…

  • CVE-2019-25753HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the…

  • CVE-2019-25752HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the…

  • CVE-2019-25751HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch,…

  • CVE-2019-25750HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels…

  • CVE-2019-25748HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL…

  • CVE-2017-20281HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch…

  • CVE-2017-20280HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the…

  • CVE-2017-20279HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to…

  • CVE-2017-20278HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL…

  • CVE-2017-20277HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL…

  • CVE-2017-20276HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy,…

  • CVE-2017-20275HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with…

  • CVE-2017-20274HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking,…

  • CVE-2017-20273HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with…

  • CVE-2017-20272HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the…

  • CVE-2017-20271HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the…

  • CVE-2017-20270HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with…

  • CVE-2017-20269HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and…

  • CVE-2017-20268HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with…

  • CVE-2017-20267HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id…

  • CVE-2017-20266HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL…

  • CVE-2017-20263HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with…

  • CVE-2017-20262HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and…

  • CVE-2017-20261HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to…

  • CVE-2017-20260HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL…

  • CVE-2017-20259HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL…

  • CVE-2017-20258HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with…

  • CVE-2017-20257HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to…

  • CVE-2017-20256HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in…

  • CVE-2017-20255HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and…

  • CVE-2017-20254HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the…

  • CVE-2017-20253HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection…

  • CVE-2017-20252HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in…

  • CVE-2018-25433HigJun 1, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted…

  • CVE-2018-25351HigMay 23, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the username parameter. Attackers can submit POST requests to the login endpoint with SQL…

  • CVE-2018-25348HigMay 23, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values…

Page 5 of 26