Vulnerabilities > Joomla > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-12711 Cross-site Scripting vulnerability in Joomla Joomla!
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9.
network
low complexity
joomla CWE-79
6.1
2018-05-22 CVE-2018-6378 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
network
low complexity
joomla CWE-79
6.1
2018-05-22 CVE-2018-11328 Cross-site Scripting vulnerability in Joomla Joomla!
An issue was discovered in Joomla! Core before 3.8.8.
network
high complexity
joomla CWE-79
4.7
2018-05-22 CVE-2018-11327 Information Exposure vulnerability in Joomla Joomla!
An issue was discovered in Joomla! Core before 3.8.8.
network
low complexity
joomla CWE-200
4.3
2018-05-22 CVE-2018-11326 Cross-site Scripting vulnerability in Joomla Joomla!
An issue was discovered in Joomla! Core before 3.8.8.
network
low complexity
joomla CWE-79
4.8
2018-05-22 CVE-2018-11324 Race Condition vulnerability in Joomla Joomla!
An issue was discovered in Joomla! Core before 3.8.8.
network
high complexity
joomla CWE-362
5.9
2018-05-22 CVE-2018-11321 Improper Input Validation vulnerability in Joomla Joomla!
An issue was discovered in com_fields in Joomla! Core before 3.8.8.
network
low complexity
joomla CWE-20
6.5
2018-01-30 CVE-2018-6380 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
network
low complexity
joomla CWE-79
6.1
2018-01-30 CVE-2018-6379 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
network
low complexity
joomla CWE-79
6.1
2018-01-30 CVE-2018-6377 Cross-site Scripting vulnerability in Joomla Joomla!
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
network
low complexity
joomla CWE-79
6.1