Show filters
389 Total Results
Displaying 31-40 of 389
Sort by:
Attacker Value
Unknown
CVE-2024-24837
Disclosure Date: February 21, 2024 (last updated February 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to WordPress: from n/a through 4.15.0.
0
Attacker Value
Unknown
CVE-2024-21728
Disclosure Date: February 15, 2024 (last updated February 16, 2024)
An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a base64 malicious URL.
0
Attacker Value
Unknown
CVE-2024-21727
Disclosure Date: February 15, 2024 (last updated February 15, 2024)
XSS vulnerability in DP Calendar component for Joomla.
0
Attacker Value
Unknown
CVE-2023-40626
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
0
Attacker Value
Unknown
CVE-2023-23755
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
0
Attacker Value
Unknown
CVE-2023-23754
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
0
Attacker Value
Unknown
CVE-2023-23751
Disclosure Date: February 01, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
0
Attacker Value
Unknown
CVE-2023-23750
Disclosure Date: February 01, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
0
Attacker Value
Unknown
CVE-2016-15016
Disclosure Date: January 08, 2023 (last updated October 20, 2023)
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The identifier of the patch is 27c1b443cff45c81d9d7d926a74c76f8b6ffc6cb. It is recommended to upgrade the affected component. The identifier VDB-217653 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-27914
Disclosure Date: November 08, 2022 (last updated December 02, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
0