Show filters
389 Total Results
Displaying 1-10 of 389
Sort by:
Attacker Value
Low
CVE-2019-11358
Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6
Attacker Value
High
CVE-2023-23752
Disclosure Date: February 16, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
1
Attacker Value
Unknown
CVE-2013-5576
Disclosure Date: October 09, 2013 (last updated October 05, 2023)
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
1
Attacker Value
Unknown
CVE-2025-22207
Disclosure Date: February 18, 2025 (last updated February 19, 2025)
Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
0
Attacker Value
Unknown
CVE-2025-22209
Disclosure Date: February 15, 2025 (last updated February 15, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.
0
Attacker Value
Unknown
CVE-2025-22208
Disclosure Date: February 15, 2025 (last updated February 15, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.
0
Attacker Value
Unknown
CVE-2025-22206
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.
0
Attacker Value
Unknown
CVE-2025-22205
Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
0
Attacker Value
Unknown
CVE-2025-22204
Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
0
Attacker Value
Unknown
CVE-2024-40749
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Access Controls allows access to protected views.
0