Vulnerabilities > Joomla > Joomla > 3.5.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-04-25 | CVE-2017-7989 | Unrestricted Upload of File with Dangerous Type vulnerability in Joomla Joomla! In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden. | 4.0 |
2017-04-25 | CVE-2017-7988 | Security Bypass vulnerability in Joomla! In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. | 5.0 |
2017-04-25 | CVE-2017-7987 | Cross-site Scripting vulnerability in Joomla Joomla! In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component. | 4.3 |
2017-04-25 | CVE-2017-7986 | Cross-site Scripting vulnerability in Joomla Joomla! In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components. | 4.3 |
2017-04-25 | CVE-2017-7985 | Cross-site Scripting vulnerability in Joomla Joomla! In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components. | 4.3 |
2017-04-25 | CVE-2017-7984 | Cross-site Scripting vulnerability in Joomla Joomla! In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. | 4.3 |
2017-04-25 | CVE-2017-7983 | Information Exposure vulnerability in Joomla Joomla! In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. | 5.0 |
2017-01-23 | CVE-2016-9081 | Credentials Management vulnerability in Joomla Joomla! Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors. | 7.5 |
2016-12-30 | CVE-2016-10045 | Command Injection vulnerability in multiple products The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. | 7.5 |
2016-12-30 | CVE-2016-10033 | Argument Injection or Modification vulnerability in multiple products The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property. | 9.8 |