CVE-2018-11325
- EPSS 0.11%
- Published 22.05.2018 15:29:00
- Last modified 21.11.2024 03:43:08
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator a...
CVE-2018-11326
- EPSS 0.07%
- Published 22.05.2018 15:29:00
- Last modified 21.11.2024 03:43:08
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a ...
CVE-2018-11327
- EPSS 0.02%
- Published 22.05.2018 15:29:00
- Last modified 21.11.2024 03:43:08
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.
CVE-2018-11328
- EPSS 0.06%
- Published 22.05.2018 15:29:00
- Last modified 21.11.2024 03:43:08
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could...
CVE-2018-6378
- EPSS 1.89%
- Published 22.05.2018 15:29:00
- Last modified 21.11.2024 04:10:35
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
CVE-2018-8045
- EPSS 65.49%
- Published 15.03.2018 01:29:03
- Last modified 21.11.2024 04:13:10
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
CVE-2018-6376
- EPSS 6.17%
- Published 30.01.2018 17:29:00
- Last modified 21.11.2024 04:10:35
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
CVE-2018-6377
- EPSS 40.06%
- Published 30.01.2018 17:29:00
- Last modified 21.11.2024 04:10:35
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
CVE-2018-6379
- EPSS 2.32%
- Published 30.01.2018 17:29:00
- Last modified 21.11.2024 04:10:35
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
CVE-2018-6380
- EPSS 2.32%
- Published 30.01.2018 17:29:00
- Last modified 21.11.2024 04:10:35
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.