Show filters
610 Total Results
Displaying 151-160 of 610
Sort by:
Attacker Value
Unknown

CVE-2018-17858

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.
0
Attacker Value
Unknown

CVE-2018-17855

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
0
Attacker Value
Unknown

CVE-2018-17857

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation.
0
Attacker Value
Unknown

CVE-2018-17859

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.
0
Attacker Value
Unknown

CVE-2018-17375

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
0
Attacker Value
Unknown

CVE-2018-14592

Disclosure Date: September 20, 2018 (last updated November 27, 2024)
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
0
Attacker Value
Unknown

CVE-2018-15880

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.
0
Attacker Value
Unknown

CVE-2018-15882

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.
0
Attacker Value
Unknown

CVE-2018-15881

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.
0
Attacker Value
Unknown

CVE-2018-12712

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.
0