Exposición de Joomla

CMS
1013
score de exposición
94.953
sitios usan
4
en explotación
60
críticos
Análisis Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

338 resultados
CVE-2010-1432Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may EPSS 1.0%CVE-2021-26028[20210308] - Core - Path Traversal within joomla/archive zip classEPSS 1.0%CVE-2021-26031[20210402] - Core - Inadequate filters on module layout settingsEPSS 1.0%CVE-2021-26038[20210704] - Core - Privilege escalation through com_installerEPSS 1.0%CVE-2013-3931Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users witEPSS 1.0%CVE-2021-26029[20210309] - Core - Inadequate filtering of form contents could allow to overwrite the author fieldEPSS 1.0%CVE-2010-1434Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain accesEPSS 0.9%CVE-2021-26040[20210801] - Core - Insufficient access control for com_media deletion endpointEPSS 0.9%CVE-2021-26027[20210307] - Core - ACL violation within com_content frontend editingEPSS 0.9%CVE-2022-23794[20220302] - Core - Path Disclosure within filesystem error messagesEPSS 0.9%CVE-2012-1562Joomla! core before 2.5.3 allows unauthorized password change.EPSS 0.9%CVE-2011-4907Joomla! 1.5x through 1.5.12: Missing JEXEC CheckEPSS 0.9%CVE-2023-39970Extension - acymailing.com - RCE in AcyMailing component for Joomla 6.7.0-8.5.0EPSS 0.9%CVE-2021-26037[20210703] - Core - Lack of enforced session terminationEPSS 0.9%CVE-2023-49708Extension - joomstar.com - SQLi vulnerability in Starshop component for Joomla 1.0.0-1.0.9EPSS 0.8%CVE-2023-40629Extension - king-products.net - SQLi vulnerability in LMS Lite component for Joomla 1.0.0-3.3.0.1EPSS 0.8%CVE-2023-49707Extension - joomlart.com - SQLi vulnerability in S5 Register module for Joomla 1.0.0-3.0.0EPSS 0.8%CVE-2011-3595Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and auEPSS 0.8%CVE-2023-40626[20231101] - Core - Exposure of environment variablesEPSS 0.8%CVE-2021-26032[20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUploadEPSS 0.8%