Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
joomla vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-1940
Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x up to and including 1.5.10 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Joomla Joomla 1.5
Joomla Joomla 1.5.6
Joomla Joomla 1.5.7
Joomla Joomla 1.5.1
Joomla Joomla 1.5.10
Joomla Joomla 1.5.8
Joomla Joomla 1.5.9
Joomla Joomla 1.5.2
Joomla Joomla 1.5.3
Joomla Joomla 1.5.4
Joomla Joomla 1.5.5
9.8
CVSSv3
CVE-2016-9081
Joomla! 3.4.4 up to and including 3.6.3 allows malicious users to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
Joomla Joomla\\! 3.6.0
Joomla Joomla\\! 3.5.1
Joomla Joomla\\! 3.4.7
Joomla Joomla\\! 3.4.4
Joomla Joomla\\! 3.4.5
Joomla Joomla\\! 3.4.6
Joomla Joomla\\! 3.6.2
Joomla Joomla\\! 3.6.1
Joomla Joomla\\! 3.5.0
Joomla Joomla\\! 3.6.3
Joomla Joomla\\! 3.4.8
1 Github repository
NA
CVE-2009-1280
Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x up to and including 1.5.9 allow remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Joomla Joomla 1.5.0
Joomla Joomla 1.5.6
Joomla Joomla 1.5.7
Joomla Joomla 1.5.8
Joomla Joomla 1.5
Joomla Joomla 1.5.4
Joomla Joomla 1.5.5
Joomla Joomla 1.5.1
Joomla Joomla 1.5.9
Joomla Joomla 1.5.2
Joomla Joomla 1.5.3
NA
CVE-2006-7008
Unspecified vulnerability in Joomla! prior to 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029.
Joomla Joomla 1.0.0
Joomla Joomla 1.0.1
Joomla Joomla 1.0.2
Joomla Joomla 1.0.7
Joomla Joomla 1.0.8
Joomla Joomla 1.0.9
Joomla Joomla 1.0.4
Joomla Joomla 1.0.6
Joomla Joomla 1.0.3
Joomla Joomla 1.0.5
NA
CVE-2014-7981
SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x prior to 3.2.3 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Joomla Joomla\\! 3.1.2
Joomla Joomla\\! 3.1.1
Joomla Joomla\\! 3.1.6
Joomla Joomla\\! 3.2.1
Joomla Joomla\\! 3.1.3
Joomla Joomla\\! 3.1.4
Joomla Joomla\\! 3.1.5
Joomla Joomla\\! 3.1.0
Joomla Joomla\\! 3.2.2
Joomla Joomla\\! 3.2.0
NA
CVE-2006-7009
Joomla! prior to 1.0.10 allows remote malicious users to spoof the frontend submission forms, which has unknown impact and attack vectors.
Joomla Joomla 1.0.4
Joomla Joomla 1.0.5
Joomla Joomla 1.0.6
Joomla Joomla 1.0.7
Joomla Joomla 1.0.0
Joomla Joomla 1.0.2
Joomla Joomla 1.0.9
Joomla Joomla 1.0.1
Joomla Joomla 1.0.3
Joomla Joomla 1.0.8
NA
CVE-2006-7010
The mosgetparam implementation in Joomla! prior to 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.
Joomla Joomla 1.0.2
Joomla Joomla 1.0.3
Joomla Joomla 1.0.4
Joomla Joomla 1.0.5
Joomla Joomla 1.0.0
Joomla Joomla 1.0.7
Joomla Joomla 1.0.9
Joomla Joomla 1.0.1
Joomla Joomla 1.0.6
Joomla Joomla 1.0.8
NA
CVE-2014-6631
Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x prior to 3.2.5 and 3.3.x prior to 3.3.4 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Joomla Joomla\\! 3.2.4
Joomla Joomla\\! 3.3.3
Joomla Joomla\\! 3.3.2
Joomla Joomla\\! 3.3.1
Joomla Joomla\\! 3.3.0
Joomla Joomla\\! 3.2.2
Joomla Joomla\\! 3.2.0
Joomla Joomla\\! 3.2.3
Joomla Joomla\\! 3.2.1
NA
CVE-2006-3480
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! prior to 1.0.10 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function, and the (2) SEF and (3) com_messages modules.
Joomla Joomla 1.0.2
Joomla Joomla 1.0.3
Joomla Joomla 1.0.7
Joomla Joomla 1.0.8
Joomla Joomla 1.0.4
Joomla Joomla 1.0.5
Joomla Joomla 1.0
Joomla Joomla 1.0.1
Joomla Joomla 1.0.9
NA
CVE-2006-3481
Multiple SQL injection vulnerabilities in Joomla! prior to 1.0.10 allow remote malicious users to execute arbitrary SQL commands via unspecified parameters involving the (1) "Remember Me" function, (2) "Related Items" module, and the (3) "Weblinks submiss...
Joomla Joomla 1.0
Joomla Joomla 1.0.1
Joomla Joomla 1.0.4
Joomla Joomla 1.0.5
Joomla Joomla 1.0.2
Joomla Joomla 1.0.3
Joomla Joomla 1.0.7
Joomla Joomla 1.0.8
Joomla Joomla 1.0.9
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »