Show filters
610 Total Results
Displaying 21-30 of 610
Sort by:
Attacker Value
Unknown

CVE-2024-21725

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
0
Attacker Value
Unknown

CVE-2024-21724

Disclosure Date: February 29, 2024 (last updated February 15, 2025)
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
Attacker Value
Unknown

CVE-2024-21723

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
Inadequate parsing of URLs could result into an open redirect.
0
Attacker Value
Unknown

CVE-2024-21722

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
0
Attacker Value
Unknown

CVE-2023-49707

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
SQLi vulnerability in S5 Register module for Joomla.
Attacker Value
Unknown

CVE-2023-40626

Disclosure Date: November 29, 2023 (last updated December 06, 2023)
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
Attacker Value
Unknown

CVE-2023-44242

Disclosure Date: October 02, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team Slideshow, Image Slider by 2J plugin <= 1.3.54 versions.
Attacker Value
Unknown

CVE-2023-39987

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions.
Attacker Value
Unknown

CVE-2020-36729

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above level access) to allow attackers to perform otherwise restricted actions and subsequently deactivate any plugins on the blog.
Attacker Value
Unknown

CVE-2023-23755

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.