Show filters
610 Total Results
Displaying 21-30 of 610
Sort by:
Attacker Value
Unknown
CVE-2024-21725
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
0
Attacker Value
Unknown
CVE-2024-21724
Disclosure Date: February 29, 2024 (last updated February 15, 2025)
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
0
Attacker Value
Unknown
CVE-2024-21723
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
Inadequate parsing of URLs could result into an open redirect.
0
Attacker Value
Unknown
CVE-2024-21722
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
0
Attacker Value
Unknown
CVE-2023-49707
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
SQLi vulnerability in S5 Register module for Joomla.
0
Attacker Value
Unknown
CVE-2023-40626
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
0
Attacker Value
Unknown
CVE-2023-44242
Disclosure Date: October 02, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team Slideshow, Image Slider by 2J plugin <= 1.3.54 versions.
0
Attacker Value
Unknown
CVE-2023-39987
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions.
0
Attacker Value
Unknown
CVE-2020-36729
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above level access) to allow attackers to perform otherwise restricted actions and subsequently deactivate any plugins on the blog.
0
Attacker Value
Unknown
CVE-2023-23755
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
0