Vulnerabilities
Vulnerable Software
Joomla:  >> Joomla!  >> 3.7.2  Security Vulnerabilities
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
CVSS Score
9.8
EPSS Score
0.024
Published
2018-01-30
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
CVSS Score
6.1
EPSS Score
0.065
Published
2018-01-30
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
CVSS Score
6.1
EPSS Score
0.01
Published
2018-01-30
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
CVSS Score
6.1
EPSS Score
0.01
Published
2018-01-30
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
CVSS Score
4.3
EPSS Score
0.0
Published
2017-11-10
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
CVSS Score
9.8
EPSS Score
0.001
Published
2017-11-10
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
CVSS Score
3.7
EPSS Score
0.0
Published
2017-09-20
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
CVSS Score
9.8
EPSS Score
0.026
Published
2017-09-20
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
CVSS Score
8.8
EPSS Score
0.003
Published
2017-08-02
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
CVSS Score
6.1
EPSS Score
0.001
Published
2017-07-26


Contact Us

Shodan ® - All rights reserved