Joomla

Joomla!

140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.61%
  • Veröffentlicht 26.05.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:46

An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.

  • EPSS 0.01%
  • Veröffentlicht 26.05.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:46

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

  • EPSS 0.01%
  • Veröffentlicht 26.05.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:47

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.

  • EPSS 46.05%
  • Veröffentlicht 14.04.2021 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:55:46

An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

  • EPSS 0.01%
  • Veröffentlicht 14.04.2021 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:55:46

An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.

  • EPSS 0.01%
  • Veröffentlicht 04.03.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:51:15

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.

  • EPSS 0.01%
  • Veröffentlicht 04.03.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:51:15

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.

  • EPSS 0.01%
  • Veröffentlicht 04.03.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:51:15

An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its ba...

  • EPSS 2.95%
  • Veröffentlicht 04.03.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:51:15

An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.

  • EPSS 2.95%
  • Veröffentlicht 04.03.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:51:15

An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.