Vulnerabilities > Joomla > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-20 CVE-2015-5608 Open Redirect vulnerability in Joomla Joomla!
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
network
low complexity
joomla CWE-601
6.1
2017-07-26 CVE-2017-11612 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
network
low complexity
joomla CWE-79
6.1
2017-07-17 CVE-2017-9934 Cross-site Scripting vulnerability in Joomla Joomla!
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-8057 Information Exposure vulnerability in Joomla Joomla!
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
network
low complexity
joomla CWE-200
5.3
2017-04-25 CVE-2017-7989 Unrestricted Upload of File with Dangerous Type vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
network
low complexity
joomla CWE-434
6.5
2017-04-25 CVE-2017-7988 Unspecified vulnerability in Joomla Joomla!
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
network
low complexity
joomla
5.3
2017-04-25 CVE-2017-7987 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7986 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7985 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
network
low complexity
joomla CWE-79
6.1
2017-04-25 CVE-2017-7984 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
network
low complexity
joomla CWE-79
6.1