Product:

Joomla\!

(Joomla)
Repositories https://github.com/joomla/joomla-cms
#Vulnerabilities 274
Date Id Summary Products Score Patch Annotated
2024-02-29 CVE-2024-21722 The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. Joomla\! N/A
2024-02-29 CVE-2024-21723 Inadequate parsing of URLs could result into an open redirect. Joomla\! N/A
2024-02-29 CVE-2024-21725 Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. Joomla\! N/A
2024-02-29 CVE-2024-21726 Inadequate content filtering leads to XSS vulnerabilities in various components. Joomla\! N/A
2024-07-09 CVE-2024-21730 The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. Joomla\! 5.4
2024-07-09 CVE-2024-21731 Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. Joomla\! 6.1
2024-07-09 CVE-2024-26278 The Custom Fields component not correctly filter inputs, leading to a XSS vector. Joomla\! 6.1
2024-02-29 CVE-2024-21724 Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. Joomla\! 6.1
2023-02-16 CVE-2023-23752 An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. Joomla\! 5.3
2005-12-31 CVE-2005-4650 Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots. Joomla\! N/A