Show filters
55 Total Results
Displaying 1-10 of 55
Sort by:
Attacker Value
Unknown
CVE-2017-14596
Disclosure Date: September 20, 2017 (last updated November 26, 2024)
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
0
Attacker Value
Unknown
CVE-2017-11364
Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
0
Attacker Value
Unknown
CVE-2017-11612
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
0
Attacker Value
Unknown
CVE-2017-7988
Disclosure Date: April 25, 2017 (last updated November 26, 2024)
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
0
Attacker Value
Unknown
CVE-2017-7983
Disclosure Date: April 25, 2017 (last updated November 26, 2024)
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
0
Attacker Value
Unknown
CVE-2017-7986
Disclosure Date: April 25, 2017 (last updated November 26, 2024)
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
0
Attacker Value
Unknown
CVE-2015-8562
Disclosure Date: December 16, 2015 (last updated October 05, 2023)
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
0
Attacker Value
Unknown
CVE-2012-2413
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie parameter to html/modules.php.
0
Attacker Value
Unknown
CVE-2012-1599
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a duplicate of CVE-2012-1611.
0
Attacker Value
Unknown
CVE-2012-1598
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."
0