Show filters
389 Total Results
Displaying 151-160 of 389
Sort by:
Attacker Value
Unknown
CVE-2018-17857
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation.
0
Attacker Value
Unknown
CVE-2018-17859
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.
0
Attacker Value
Unknown
CVE-2018-15880
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.
0
Attacker Value
Unknown
CVE-2018-15882
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.
0
Attacker Value
Unknown
CVE-2018-15881
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.
0
Attacker Value
Unknown
CVE-2018-12712
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.
0
Attacker Value
Unknown
CVE-2018-12711
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.
0
Attacker Value
Unknown
CVE-2018-11322
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
0
Attacker Value
Unknown
CVE-2018-11321
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
0
Attacker Value
Unknown
CVE-2018-11328
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.
0