Vulnerabilities > Joomla > Joomla > 3.9.2

DATE CVE VULNERABILITY TITLE RISK
2020-07-15 CVE-2020-15697 Incorrect Permission Assignment for Critical Resource vulnerability in Joomla Joomla!
An issue was discovered in Joomla! through 3.9.19.
network
low complexity
joomla CWE-732
4.0
2020-07-15 CVE-2020-15696 Cross-site Scripting vulnerability in Joomla Joomla!
An issue was discovered in Joomla! through 3.9.19.
network
joomla CWE-79
4.3
2020-07-15 CVE-2020-15695 Cross-Site Request Forgery (CSRF) vulnerability in Joomla Joomla!
An issue was discovered in Joomla! through 3.9.19.
network
joomla CWE-352
6.8
2020-06-02 CVE-2020-13763 Improper Preservation of Permissions vulnerability in Joomla Joomla!
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
network
low complexity
joomla CWE-281
5.0
2020-06-02 CVE-2020-13762 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
network
joomla CWE-79
4.3
2020-06-02 CVE-2020-13761 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
network
joomla CWE-79
4.3
2020-06-02 CVE-2020-13760 Cross-Site Request Forgery (CSRF) vulnerability in Joomla Joomla!
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
network
joomla CWE-352
6.8
2020-04-21 CVE-2020-11891 Incorrect Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.17.
network
low complexity
joomla CWE-863
5.0
2020-04-21 CVE-2020-11890 Improper Input Validation vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.17.
network
low complexity
joomla CWE-20
5.0
2020-04-21 CVE-2020-11889 Incorrect Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.17.
network
low complexity
joomla CWE-863
5.0