Show filters
389 Total Results
Displaying 61-70 of 389
Sort by:
Attacker Value
Unknown

CVE-2010-1433

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
Attacker Value
Unknown

CVE-2010-1434

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
Attacker Value
Unknown

CVE-2021-26034

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.
Attacker Value
Unknown

CVE-2021-26033

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.
Attacker Value
Unknown

CVE-2021-26032

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
Attacker Value
Unknown

CVE-2021-26031

Disclosure Date: April 14, 2021 (last updated November 28, 2024)
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.
Attacker Value
Unknown

CVE-2021-26030

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
Attacker Value
Unknown

CVE-2021-26027

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
Attacker Value
Unknown

CVE-2021-23131

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
Attacker Value
Unknown

CVE-2021-26028

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.