Product:

Joomla\!

(Joomla)
Repositories https://github.com/joomla/joomla-cms
#Vulnerabilities 259
Date Id Summary Products Score Patch Annotated
2019-12-18 CVE-2019-19846 In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. Joomla\! N/A
2019-12-18 CVE-2019-19845 In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. Joomla\! N/A
2019-11-06 CVE-2019-18674 An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure. Joomla\! N/A
2019-11-06 CVE-2019-18650 An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. Joomla\! N/A
2017-04-25 CVE-2017-7988 In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. Joomla\! 5.3
2017-09-20 CVE-2017-14595 In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state. Joomla\! 3.7
2019-09-24 CVE-2019-16725 In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. Joomla\! N/A
2019-08-14 CVE-2019-15028 In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. Joomla\! 5.3
2019-08-05 CVE-2019-14654 In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9. Joomla\! 8.8
2019-05-20 CVE-2019-11809 An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector. Joomla\! 6.1