PRIOn Logo

Search KB


Search our pre-analyzed vulnerability database

Total Results: 734

of 37

Published:   Updated:

Vulnerability Type: Information disclosure

Vendor(s):  Joomla
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v37.5

The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

Published:   Updated:

Vulnerability Type: Information disclosure

Vendor(s):  Acymailing
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v35.3

Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.

Published:   Updated:

Vulnerability Type: Improper access control

Vendor(s):  Acymailing
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v34.3

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

Published:   Updated:

Vulnerability Type: Improper access control

Vendor(s):  Acymailing
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v34.3

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.

Published:   Updated:

Vulnerability Type: Design/Logic Flaw

Vendor(s):  Acymailing
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v36.1

Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

Published:   Updated:

Vulnerability Type: Design/Logic Flaw

Vendor(s):  Acyba
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

Published:   Updated:

Vulnerability Type: Cross site scripting

Vendor(s):  Admiror-design-studio
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v36.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Hikashop
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Braincert
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Mooj
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Creative-solutions
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Bestaddon
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

Published:   Updated:

Vulnerability Type: Cross site scripting

Vendor(s):  Advcomsys
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v36.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

Published:   Updated:

Vulnerability Type: Design/Logic Flaw

Vendor(s):  Joomla
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v37.5

An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

Published:   Updated:

Vulnerability Type: Input validation

Vendor(s):  Joomla
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v36.1

An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Vi-solutions
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.

Published:   Updated:

Vulnerability Type: Cross site scripting

Vendor(s):  Acymailing
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v36.1

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

Published:   Updated:

Vulnerability Type: Path traversal

Vendor(s):  Acymailing
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v37.5

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below 8.3.0.

Published:   Updated:

Vulnerability Type: Unrestricted file upload

Vendor(s):  Acymailing
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

Published:   Updated:

Vulnerability Type: Improper access control

Vendor(s):  Joomla
Urgent
Remediate Within one Week
CVSS v2N/ACVSS v35.3

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

of 37