Show filters
610 Total Results
Displaying 81-90 of 610
Sort by:
Attacker Value
Unknown

CVE-2020-35610

Disclosure Date: November 24, 2020 (last updated November 28, 2024)
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
Attacker Value
Unknown

CVE-2020-35614

Disclosure Date: November 24, 2020 (last updated November 28, 2024)
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
Attacker Value
Unknown

CVE-2020-35616

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.
Attacker Value
Unknown

CVE-2020-35611

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
Attacker Value
Unknown

CVE-2020-35615

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
Attacker Value
Unknown

CVE-2020-35612

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
Attacker Value
Unknown

CVE-2020-24598

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
Attacker Value
Unknown

CVE-2020-24599

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
Attacker Value
Unknown

CVE-2020-15697

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
Attacker Value
Unknown

CVE-2020-15696

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.