Show filters
610 Total Results
Displaying 41-50 of 610
Sort by:
Attacker Value
Unknown

CVE-2022-23802

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private information and components, possibility to view other users' information.
Attacker Value
Unknown

CVE-2022-29426

Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.
Attacker Value
Unknown

CVE-2022-23800

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
Attacker Value
Unknown

CVE-2022-23801

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
Attacker Value
Unknown

CVE-2022-23798

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
Attacker Value
Unknown

CVE-2022-23796

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
Attacker Value
Unknown

CVE-2022-23797

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.
Attacker Value
Unknown

CVE-2022-23793

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
Attacker Value
Unknown

CVE-2022-23799

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.
Attacker Value
Unknown

CVE-2022-23794

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.