Joomla
joomla
546 CVEs • 147 products
Products (147)
Click to collapseToggle
Products (147)
Click to collapse
CVEs (546)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages...Show more |
Improper Access Controls allows access to protected views. |
Lack of output escaping in the id attribute of menu lists. |
Various module chromes didn't properly process inputs, leading to XSS vectors. |
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. |
Improper Access Controls allows backend users to overwrite their username when disallowed. |
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. |
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. |
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. |
The wrapper extensions do not correctly validate inputs, leading to XSS vectors. |
The Custom Fields component not correctly filter inputs, leading to a XSS vector. |
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. |
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. |
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. |
Inadequate content filtering leads to XSS vulnerabilities in various components. |
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. |
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. |
Inadequate parsing of URLs could result into an open redirect. |
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. |