Vulnerabilities (CVE)

Filtered by vendor Joomla Subscribe
Total 917 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13763 1 Joomla 1 Joomla\! 2020-10-19 5.0 MEDIUM 7.5 HIGH
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
CVE-2020-13760 1 Joomla 1 Joomla\! 2020-10-19 6.8 MEDIUM 8.8 HIGH
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
CVE-2020-13761 1 Joomla 1 Joomla\! 2020-10-19 4.3 MEDIUM 6.1 MEDIUM
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
CVE-2020-24598 1 Joomla 1 Joomla\! 2020-08-28 5.8 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
CVE-2020-24599 1 Joomla 1 Joomla\! 2020-08-28 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
CVE-2019-14654 1 Joomla 1 Joomla\! 2020-08-24 6.5 MEDIUM 8.8 HIGH
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.
CVE-2019-7743 1 Joomla 1 Joomla\! 2020-08-24 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
CVE-2018-17856 1 Joomla 1 Joomla\! 2020-08-24 6.5 MEDIUM 7.2 HIGH
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
CVE-2019-15028 1 Joomla 1 Joomla\! 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
CVE-2019-10946 1 Joomla 1 Joomla\! 2020-08-24 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.
CVE-2019-9713 1 Joomla 1 Joomla\! 2020-08-24 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
CVE-2018-17855 1 Joomla 1 Joomla\! 2020-08-24 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
CVE-2019-7739 1 Joomla 1 Joomla\! 2020-08-24 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this.
CVE-2020-15700 1 Joomla 1 Joomla\! 2020-07-15 6.8 MEDIUM 6.3 MEDIUM
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
CVE-2020-15699 1 Joomla 1 Joomla\! 2020-07-15 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
CVE-2020-15697 1 Joomla 1 Joomla\! 2020-07-15 4.0 MEDIUM 4.3 MEDIUM
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
CVE-2020-15695 1 Joomla 1 Joomla\! 2020-07-15 6.8 MEDIUM 6.3 MEDIUM
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
CVE-2020-15696 1 Joomla 1 Joomla\! 2020-07-15 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
CVE-2020-13762 1 Joomla 1 Joomla\! 2020-06-03 4.3 MEDIUM 6.1 MEDIUM
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
CVE-2020-11890 1 Joomla 1 Joomla\! 2020-04-29 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.