Joomla

Joomla!

158 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 09.07.2024 17:15:14
  • Zuletzt bearbeitet 13.03.2025 15:15:41

Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.

  • EPSS 0.45%
  • Veröffentlicht 09.07.2024 17:15:14
  • Zuletzt bearbeitet 13.03.2025 16:15:18

The Custom Fields component not correctly filter inputs, leading to a XSS vector.

  • EPSS 0.81%
  • Veröffentlicht 29.11.2023 13:15:07
  • Zuletzt bearbeitet 21.11.2024 08:19:51

The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

  • EPSS 0.41%
  • Veröffentlicht 30.05.2023 17:15:09
  • Zuletzt bearbeitet 09.01.2025 22:15:25

An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

  • EPSS 0.56%
  • Veröffentlicht 30.05.2023 17:15:09
  • Zuletzt bearbeitet 09.01.2025 22:15:26

An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

  • EPSS 0.47%
  • Veröffentlicht 08.11.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 06:56:27

An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.

  • EPSS 0.37%
  • Veröffentlicht 25.10.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 06:56:27

An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

  • EPSS 0.52%
  • Veröffentlicht 25.10.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:56:27

An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.

  • EPSS 0.52%
  • Veröffentlicht 31.08.2022 10:15:15
  • Zuletzt bearbeitet 21.11.2024 06:56:27

An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.

Exploit
  • EPSS 2.08%
  • Veröffentlicht 30.03.2022 16:15:11
  • Zuletzt bearbeitet 21.11.2024 06:49:16

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.