Joomla

Joomla!

158 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 28.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:38:48

An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

Exploit
  • EPSS 0.81%
  • Veröffentlicht 22.01.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 01:30:49

Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.

  • EPSS 0.88%
  • Veröffentlicht 15.01.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 01:33:16

Joomla! 1.5x through 1.5.12: Missing JEXEC Check

  • EPSS 0.89%
  • Veröffentlicht 15.01.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 01:37:12

Joomla! core before 2.5.3 allows unauthorized password change.

  • EPSS 8.9%
  • Veröffentlicht 15.01.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 01:37:13

Joomla! before 2.5.3 allows Admin Account Creation.

  • EPSS 1.1%
  • Veröffentlicht 18.12.2019 04:15:15
  • Zuletzt bearbeitet 21.11.2024 04:35:30

In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.

  • EPSS 1.69%
  • Veröffentlicht 18.12.2019 04:15:15
  • Zuletzt bearbeitet 21.11.2024 04:35:31

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

  • EPSS 1.09%
  • Veröffentlicht 06.11.2019 02:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.

  • EPSS 0.45%
  • Veröffentlicht 06.11.2019 02:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:27

An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

  • EPSS 0.67%
  • Veröffentlicht 24.09.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:04

In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.