Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Joomla\!
(Joomla)Repositories | https://github.com/joomla/joomla-cms |
#Vulnerabilities | 259 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-12-18 | CVE-2019-19846 | In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. | Joomla\! | N/A | ||
2019-12-18 | CVE-2019-19845 | In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. | Joomla\! | N/A | ||
2019-11-06 | CVE-2019-18674 | An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure. | Joomla\! | N/A | ||
2019-11-06 | CVE-2019-18650 | An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. | Joomla\! | N/A | ||
2017-04-25 | CVE-2017-7988 | In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. | Joomla\! | 5.3 | ||
2017-09-20 | CVE-2017-14595 | In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state. | Joomla\! | 3.7 | ||
2019-09-24 | CVE-2019-16725 | In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. | Joomla\! | N/A | ||
2019-08-14 | CVE-2019-15028 | In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. | Joomla\! | 5.3 | ||
2019-08-05 | CVE-2019-14654 | In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9. | Joomla\! | 8.8 | ||
2019-05-20 | CVE-2019-11809 | An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector. | Joomla\! | 6.1 |