CVE-2024-27187
- EPSS 0.01%
- Veröffentlicht 20.08.2024 16:15:10
- Zuletzt bearbeitet 04.06.2025 20:58:17
Improper Access Controls allows backend users to overwrite their username when disallowed.
CVE-2024-21731
- EPSS 0.04%
- Veröffentlicht 09.07.2024 17:15:14
- Zuletzt bearbeitet 13.03.2025 15:15:41
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
CVE-2024-26278
- EPSS 0.01%
- Veröffentlicht 09.07.2024 17:15:14
- Zuletzt bearbeitet 13.03.2025 16:15:18
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
CVE-2023-40626
- EPSS 0.03%
- Veröffentlicht 29.11.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 08:19:51
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
CVE-2023-23754
- EPSS 0.02%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 09.01.2025 22:15:25
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
CVE-2023-23755
- EPSS 0%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 09.01.2025 22:15:26
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
CVE-2023-23752
- EPSS 94.53%
- Veröffentlicht 16.02.2023 17:15:10
- Zuletzt bearbeitet 07.02.2025 14:58:09
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
CVE-2022-27914
- EPSS 0.05%
- Veröffentlicht 08.11.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:56:27
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
CVE-2022-27913
- EPSS 0.05%
- Veröffentlicht 25.10.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:56:27
An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
CVE-2022-27912
- EPSS 0.01%
- Veröffentlicht 25.10.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:56:27
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.