Vulnerabilities
CVE-2024-27187
HIGHImproper Access Controls allows backend users to overwrite their username when disallowed.
CVE-2023-23752
MEDIUMAn issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
CVE-2011-4908
UNKNOWNTinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
CVE-2011-4906
UNKNOWNTiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
CVE-2011-1151
UNKNOWNJoomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
CVE-2011-4912
UNKNOWNJoomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
CVE-2011-3629
UNKNOWNJoomla! core 1.7.1 allows information disclosure due to weak encryption
CVE-2011-4937
UNKNOWNJoomla! 1.7.1 has core information disclosure due to inadequate error checking.
CVE-2011-3595
UNKNOWNMultiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
CVE-2011-4907
UNKNOWNJoomla! 1.5x through 1.5.12: Missing JEXEC Check
CVE-2012-1563
UNKNOWNJoomla! before 2.5.3 allows Admin Account Creation.
CVE-2012-1562
UNKNOWNJoomla! core before 2.5.3 allows unauthorized password change.