<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Joomla! (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/joomla.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/joomla-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Joomla! (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2018-25433 – Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25433</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25433</strong></p>
  <p>Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernam…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25381 – Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25381</guid>
    <pubDate>Mon, 25 May 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25381</strong></p>
  <p>Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract sensitive database information including credentials and server details.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25380 – Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25380</guid>
    <pubDate>Mon, 25 May 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25380</strong></p>
  <p>Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view with malicious SQL payloads to extract sensitive database information and server data.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25351 – Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25351</guid>
    <pubDate>Sat, 23 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25351</strong></p>
  <p>Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the username parameter. Attackers can submit POST requests to the login endpoint with SQL injection payloads in the username field to extract database information including user credentials and system details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25348 – Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25348</guid>
    <pubDate>Sat, 23 May 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25348</strong></p>
  <p>Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25330 – Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25330</guid>
    <pubDate>Sun, 17 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25330</strong></p>
  <p>Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37226 – Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37226</guid>
    <pubDate>Wed, 13 May 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37226</strong></p>
  <p>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information using automated tools.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37224 – Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37224</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37224</strong></p>
  <p>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37219 – Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37219</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37219</strong></p>
  <p>Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories outside the intended web root.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37218 – Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37218</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37218</strong></p>
  <p>Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47930 – Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47930</guid>
    <pubDate>Sun, 10 May 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47930</strong></p>
  <p>Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34424 – Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34424</guid>
    <pubDate>Thu, 09 Apr 2026 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34424</strong></p>
  <p>Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers, establish authenticated backdoors accepting arbitrary PHP code or OS commands, create hi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21627 – The vulnerability was rooted in how the Tassos Framework plugin handled specific...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21627</guid>
    <pubDate>Fri, 20 Feb 2026 15:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21627</strong></p>
  <p>The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.</p>
  <p><strong>CVSS:</strong> 9.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21625 – User provided uploads to the Easy Discuss component for Joomla aren't properly v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21625</guid>
    <pubDate>Fri, 16 Jan 2026 15:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21625</strong></p>
  <p>User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-40636 – SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40636</guid>
    <pubDate>Fri, 03 Oct 2025 12:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-40636</strong></p>
  <p>SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoints where the plugin counts visits.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54301 – A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54301</guid>
    <pubDate>Mon, 25 Aug 2025 07:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54301</strong></p>
  <p>A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54300 – A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54300</guid>
    <pubDate>Mon, 25 Aug 2025 07:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54300</strong></p>
  <p>A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54475 – A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54475</guid>
    <pubDate>Fri, 15 Aug 2025 12:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54475</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54474 – A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54474</guid>
    <pubDate>Fri, 15 Aug 2025 12:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54474</strong></p>
  <p>A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54473 – An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54473</guid>
    <pubDate>Fri, 15 Aug 2025 12:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54473</strong></p>
  <p>An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54299 – A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54299</guid>
    <pubDate>Mon, 28 Jul 2025 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54299</strong></p>
  <p>A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54298 – A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54298</guid>
    <pubDate>Mon, 28 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54298</strong></p>
  <p>A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54297 – A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54297</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54297</strong></p>
  <p>A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54296 – A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54296</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54296</strong></p>
  <p>A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54294 – A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54294</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54294</strong></p>
  <p>A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50127 – A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50127</guid>
    <pubDate>Wed, 23 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50127</strong></p>
  <p>A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49486 – A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49486</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49486</strong></p>
  <p>A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49485 – A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49485</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49485</strong></p>
  <p>A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49484 – A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49484</guid>
    <pubDate>Fri, 18 Jul 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49484</strong></p>
  <p>A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-26855 – A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26855</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-26855</strong></p>
  <p>A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-26854 – A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26854</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-26854</strong></p>
  <p>A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49468 – A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49468</guid>
    <pubDate>Fri, 13 Jun 2025 10:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49468</strong></p>
  <p>A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-49467 – A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49467</guid>
    <pubDate>Thu, 12 Jun 2025 16:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49467</strong></p>
  <p>A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32465 – A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32465</guid>
    <pubDate>Wed, 11 Jun 2025 20:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32465</strong></p>
  <p>A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30085 – Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for J...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30085</guid>
    <pubDate>Wed, 11 Jun 2025 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30085</strong></p>
  <p>Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22210 – A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22210</guid>
    <pubDate>Tue, 25 Feb 2025 06:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22210</strong></p>
  <p>A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22205 – Improper handling of input variables lead to multiple path traversal vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22205</guid>
    <pubDate>Tue, 04 Feb 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22205</strong></p>
  <p>Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22204 – Improper control of generation of code in the sourcerer extension for Joomla in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22204</guid>
    <pubDate>Tue, 04 Feb 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22204</strong></p>
  <p>Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40744 – Unrestricted file upload via security bypass in Convert Forms component for Joom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40744</guid>
    <pubDate>Wed, 04 Dec 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40744</strong></p>
  <p>Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-11145 – Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11145</guid>
    <pubDate>Tue, 26 Nov 2024 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-11145</strong></p>
  <p>Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5736 – Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5736</guid>
    <pubDate>Fri, 28 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5736</strong></p>
  <p>Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5735 – Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelpe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5735</guid>
    <pubDate>Fri, 28 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5735</strong></p>
  <p>Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49708 – SQLi vulnerability in Starshop component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49708</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49708</strong></p>
  <p>SQLi vulnerability in Starshop component for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49707 – SQLi vulnerability in S5 Register module for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49707</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49707</strong></p>
  <p>SQLi vulnerability in S5 Register module for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40630 – Unauthenticated LFI/SSRF in JCDashboards component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40630</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40630</strong></p>
  <p>Unauthenticated LFI/SSRF in JCDashboards component for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40629 – SQLi vulnerability in LMS Lite component for Joomla.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40629</guid>
    <pubDate>Thu, 14 Dec 2023 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40629</strong></p>
  <p>SQLi vulnerability in LMS Lite component for Joomla.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39970 – Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing comp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39970</guid>
    <pubDate>Thu, 17 Aug 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39970</strong></p>
  <p>Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23755 – An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limitin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23755</guid>
    <pubDate>Tue, 30 May 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23755</strong></p>
  <p>An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23753 – The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23753</guid>
    <pubDate>Sun, 23 Apr 2023 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23753</strong></p>
  <p>The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28733 – AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28733</guid>
    <pubDate>Thu, 30 Mar 2023 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28733</strong></p>
  <p>AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office.   This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-28731 – AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28731</guid>
    <pubDate>Thu, 30 Mar 2023 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-28731</strong></p>
  <p>AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected.     This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23802 – Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23802</guid>
    <pubDate>Fri, 06 May 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23802</strong></p>
  <p>Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private information and components, possibility to view other users' information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23799 – An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumsta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23799</guid>
    <pubDate>Wed, 30 Mar 2022 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23799</strong></p>
  <p>An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23797 – An issue was discovered in Joomla! 3.0.0 through 3.10.6 &amp; 4.0.0 through 4.1.0. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23797</guid>
    <pubDate>Wed, 30 Mar 2022 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23797</strong></p>
  <p>An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23795 – An issue was discovered in Joomla! 2.5.0 through 3.10.6 &amp; 4.0.0 through 4.1.0. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23795</guid>
    <pubDate>Wed, 30 Mar 2022 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23795</strong></p>
  <p>An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23793 – An issue was discovered in Joomla! 3.0.0 through 3.10.6 &amp; 4.0.0 through 4.1.0. E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23793</guid>
    <pubDate>Wed, 30 Mar 2022 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23793</strong></p>
  <p>An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-26040 – An issue was discovered in Joomla! 4.0.0. The media manager does not correctly c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26040</guid>
    <pubDate>Tue, 24 Aug 2021 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-26040</strong></p>
  <p>An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26038 – An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26038</guid>
    <pubDate>Wed, 07 Jul 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26038</strong></p>
  <p>An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26036 – An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26036</guid>
    <pubDate>Wed, 07 Jul 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26036</strong></p>
  <p>An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1435 – Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1435</guid>
    <pubDate>Mon, 21 Jun 2021 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1435</strong></p>
  <p>Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1434 – Joomla! Core is prone to a session fixation vulnerability. An attacker may lever...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1434</guid>
    <pubDate>Mon, 21 Jun 2021 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1434</strong></p>
  <p>Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1433 – Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1433</guid>
    <pubDate>Mon, 21 Jun 2021 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1433</strong></p>
  <p>Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Joomla! Core versions 1.5.x…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1432 – Joomla! Core is prone to an information disclosure vulnerability. Attackers can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1432</guid>
    <pubDate>Mon, 21 Jun 2021 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1432</strong></p>
  <p>Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-23132 – An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23132</guid>
    <pubDate>Thu, 04 Mar 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-23132</strong></p>
  <p>An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-23131 – An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23131</guid>
    <pubDate>Thu, 04 Mar 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-23131</strong></p>
  <p>An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-23128 – An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23128</guid>
    <pubDate>Thu, 04 Mar 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-23128</strong></p>
  <p>An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-23127 – An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23127</guid>
    <pubDate>Thu, 04 Mar 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-23127</strong></p>
  <p>An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35616 – An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35616</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35616</strong></p>
  <p>An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35613 – An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blackli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35613</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35613</strong></p>
  <p>An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35612 – An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35612</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35612</strong></p>
  <p>An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35611 – An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configurati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35611</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35611</strong></p>
  <p>An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35610 – An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35610</guid>
    <pubDate>Mon, 28 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35610</strong></p>
  <p>An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-22274 – JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a cus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22274</guid>
    <pubDate>Wed, 04 Nov 2020 18:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-22274</strong></p>
  <p>JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-19455 – SQL injection exists in the jdownloads 3.2.63 component for Joomla! via componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19455</guid>
    <pubDate>Fri, 25 Sep 2020 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-19455</strong></p>
  <p>SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-19451 – SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19451</guid>
    <pubDate>Fri, 25 Sep 2020 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-19451</strong></p>
  <p>SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-19450 – SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19450</guid>
    <pubDate>Fri, 25 Sep 2020 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-19450</strong></p>
  <p>SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-19447 – SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19447</guid>
    <pubDate>Thu, 24 Sep 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-19447</strong></p>
  <p>SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25751 – The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the admini...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25751</guid>
    <pubDate>Fri, 18 Sep 2020 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25751</strong></p>
  <p>The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-23971 – gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-23971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-23971</guid>
    <pubDate>Tue, 01 Sep 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-23971</strong></p>
  <p>gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-23971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-23972 – In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-23972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-23972</guid>
    <pubDate>Thu, 27 Aug 2020 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-23972</strong></p>
  <p>In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-23972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13996 – The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13996</guid>
    <pubDate>Tue, 09 Jun 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13996</strong></p>
  <p>The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13763 – In Joomla! before 3.9.19, the default settings of the global textfilter configur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13763</guid>
    <pubDate>Tue, 02 Jun 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13763</strong></p>
  <p>In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13760 – In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13760</guid>
    <pubDate>Tue, 02 Jun 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13760</strong></p>
  <p>In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10243 – An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10243</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10243</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10241 – An issue was discovered in Joomla! before 3.9.16. Missing token checks in the im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10241</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10241</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10239 – An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10239</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10239</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10238 – An issue was discovered in Joomla! before 3.9.16. Various actions in com_templat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10238</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10238</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7342 – JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Q...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7342</guid>
    <pubDate>Mon, 09 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7342</strong></p>
  <p>JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7341 – JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7341</guid>
    <pubDate>Mon, 09 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7341</strong></p>
  <p>JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7340 – JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7340</guid>
    <pubDate>Mon, 09 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7340</strong></p>
  <p>JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7339 – JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7339</guid>
    <pubDate>Mon, 09 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7339</strong></p>
  <p>JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7338 – SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7338</guid>
    <pubDate>Mon, 09 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7338</strong></p>
  <p>SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4908 – TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4908</guid>
    <pubDate>Wed, 12 Feb 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4908</strong></p>
  <p>TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4906 – Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4906</guid>
    <pubDate>Wed, 12 Feb 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4906</strong></p>
  <p>Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-8739 – Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8739</guid>
    <pubDate>Sat, 08 Feb 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-8739</strong></p>
  <p>Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-1151 – Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_orde...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1151</guid>
    <pubDate>Wed, 05 Feb 2020 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-1151</strong></p>
  <p>Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-4937 – Joomla! 1.7.1 has core information disclosure due to inadequate error checking.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4937</guid>
    <pubDate>Tue, 04 Feb 2020 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-4937</strong></p>
  <p>Joomla! 1.7.1 has core information disclosure due to inadequate error checking.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-3629 – Joomla! core 1.7.1 allows information disclosure due to weak encryption</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3629</guid>
    <pubDate>Tue, 04 Feb 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-3629</strong></p>
  <p>Joomla! core 1.7.1 allows information disclosure due to weak encryption</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8420 – An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8420</guid>
    <pubDate>Tue, 28 Jan 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8420</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8419 – An issue was discovered in Joomla! before 3.9.15. Missing token checks in the ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8419</guid>
    <pubDate>Tue, 28 Jan 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8419</strong></p>
  <p>An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8419">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
