joomla

515 tracked vulnerabilities.

CVE-2020-35613 CRITICAL
Joomla! 3.0.0-3.9.22 - SQL Injection in Backend User List
Dec 28, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-35612 HIGH
Joomla! 2.5.0-3.9.22 - Path Traversal via mod_random_image Folder Parameter
Dec 28, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-35611 HIGH
Joomla! 2.5.0-3.9.22 - Unauthenticated Exposure of Sensitive Information in Global Configuration Page
Dec 28, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-35610 HIGH
Joomla! 2.5.0-3.9.22 - Unauthenticated Information Disclosure via com_finder Autosuggestion
Dec 28, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-24599 MEDIUM
Joomla! 3.9.0-3.9.20 - Cross-Site Scripting in mod_latestactions
Aug 26, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-24598 MEDIUM
Joomla! 3.0.0-3.9.21 - Open Redirect in com_content Vote Feature
Aug 26, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-15700 MEDIUM
Joomla! 3.7.0-3.9.19 - Cross-Site Request Forgery via com_installer AJAX Install Endpoint
Jul 15, 2020
CVSS 6.3
EPSS 0.00
CVE-2020-15699 MEDIUM
Joomla! 2.5.0-3.9.19 - Insufficient Verification of Data Authenticity in Usergroups Table
Jul 15, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-15698 MEDIUM
Joomla! 3.0.0-3.9.19 - Unprotected Credential Exposure in System Information Screen
Jul 15, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-15697 MEDIUM
Joomla! 3.0.0-3.9.19 - Variable Tampering via User Table Class
Jul 15, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-15696 MEDIUM
Joomla! 3.0.0-3.9.19 - Cross-Site Scripting in mod_random_image
Jul 15, 2020
CVSS 6.1
EPSS 0.03
CVE-2020-15695 MEDIUM
Joomla! 3.9.0-3.9.19 - Cross-Site Request Forgery in com_privacy Remove Request Feature
Jul 15, 2020
CVSS 6.3
EPSS 0.00
CVE-2020-13763 HIGH
Joomla! < 3.9.19 - Unauthenticated HTML Injection via Global Textfilter Configuration
Jun 02, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-13762 MEDIUM
Joomla! 3.9.0-3.9.18 - Cross-Site Scripting in com_modules Tag Option
Jun 02, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-13761 MEDIUM
Joomla! < 3.9.19 - Cross-Site Scripting in Articles Module Heading Tag Option
Jun 02, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-13760 HIGH
Joomla! < 3.9.19 - Cross-Site Request Forgery in com_postinstall
Jun 02, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-11891 MEDIUM
Joomla! <3.9.17 - Privilege Escalation
Apr 21, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-11890 MEDIUM
Joomla! < 3.9.17 - Improper Input Validation in Usergroup Table
Apr 21, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-11889 MEDIUM
Joomla! <3.9.17 - Privilege Escalation
Apr 21, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-10243 CRITICAL
Joomla! < 3.9.16 - SQL Injection in Featured Articles Menu Parameters
Mar 16, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-10242 MEDIUM
Joomla! < 3.9.16 - Cross-Site Scripting in Protostar and Beez3 CSS Selectors
Mar 16, 2020
CVSS 6.1
EPSS 0.02
CVE-2020-10241 HIGH
Joomla! 3.2.0-3.9.15 - Cross-Site Request Forgery in com_templates Image Actions
Mar 16, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-10240 MEDIUM
Joomla! 3.0.0-3.9.15 - User Identifier Collision via Missing Length Checks
Mar 16, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-10239 HIGH
Joomla! 3.7.0-3.9.15 - Incorrect Access Control in com_fields SQL Fieldtype
Mar 16, 2020
CVSS 8.8
EPSS 0.02
CVE-2020-10238 HIGH
Joomla! < 3.9.16 - Incorrect Access Control in com_templates
Mar 16, 2020
CVSS 7.5
EPSS 0.03