Show filters
389 Total Results
Displaying 1-10 of 389
Sort by:
Attacker Value
Low

CVE-2019-11358

Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Attacker Value
High

CVE-2023-23752

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Attacker Value
Unknown

CVE-2013-5576

Disclosure Date: October 09, 2013 (last updated October 05, 2023)
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
1
Attacker Value
Unknown

CVE-2025-22207

Disclosure Date: February 18, 2025 (last updated February 19, 2025)
Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
0
Attacker Value
Unknown

CVE-2025-22209

Disclosure Date: February 15, 2025 (last updated February 15, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.
0
Attacker Value
Unknown

CVE-2025-22208

Disclosure Date: February 15, 2025 (last updated February 15, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.
0
Attacker Value
Unknown

CVE-2025-22206

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.
0
Attacker Value
Unknown

CVE-2025-22205

Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
0
Attacker Value
Unknown

CVE-2025-22204

Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
0
Attacker Value
Unknown

CVE-2024-40749

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Access Controls allows access to protected views.
0