CVE-2020-35611
- EPSS 0.01%
- Published 28.12.2020 20:15:12
- Last modified 21.11.2024 05:27:42
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
CVE-2020-35612
- EPSS 0.01%
- Published 28.12.2020 20:15:12
- Last modified 21.11.2024 05:27:42
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
CVE-2020-35613
- EPSS 1.17%
- Published 28.12.2020 20:15:12
- Last modified 21.11.2024 05:27:42
An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
CVE-2020-35614
- EPSS 0.01%
- Published 28.12.2020 20:15:12
- Last modified 21.11.2024 05:27:42
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
CVE-2020-35615
- EPSS 0%
- Published 28.12.2020 20:15:12
- Last modified 21.11.2024 05:27:42
An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
CVE-2020-24599
- EPSS 0.86%
- Published 26.08.2020 22:15:14
- Last modified 21.11.2024 05:15:07
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
CVE-2020-24598
- EPSS 0.05%
- Published 26.08.2020 22:15:13
- Last modified 21.11.2024 05:15:07
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
CVE-2020-15695
- EPSS 0.01%
- Published 15.07.2020 16:15:11
- Last modified 21.11.2024 05:06:02
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
CVE-2020-15696
- EPSS 2.78%
- Published 15.07.2020 16:15:11
- Last modified 21.11.2024 05:06:02
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
CVE-2020-15697
- EPSS 0.01%
- Published 15.07.2020 16:15:11
- Last modified 21.11.2024 05:06:02
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.