Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Joomla! 1.x
This vulnerability report for Joomla! 1.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Joomla! 1.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor N/A

Product Link View Here (Link to external site)

Affected By 26 Secunia advisories
82 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 0% (0 of 26 Secunia advisories)

Most Critical Unpatched
There are no unpatched Secunia advisories affecting this product, when all vendor patches are applied..




26 Secunia Advisories in 2003-2009
Secunia has issued a total of 26 Secunia advisories in 2003-2009 for Joomla! 1.x. Currently, 0% (0 out of 26) are marked as unpatched.

More information about the specific Secunia advisories affecting Joomla! 1.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Joomla! Article Manipulation and Version Information Disclosure
Vendor Patch. Secunia Advisory 1 of 7 in 2009. 617 views.
Release Date:
2009-11-05
Secunia Advisory ID:
SA37262
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Exposure of system information
Where:
From remote
Short Description:
Some security issues have been reported in Joomla!, which can be exploited by malicious people to disclose version information and by malicious users to manipulate certain data. [Read More]


Joomla! "com_mailto" Timeout Bypass
Vendor Patch. Secunia Advisory 2 of 7 in 2009. 1,199 views.
Release Date:
2009-07-31
Secunia Advisory ID:
SA36097
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
A weakness has been reported in Joomla!, which can be exploited by malicious people to bypass certain restrictions. [Read More]


Joomla! Information Disclosure and File Upload Vulnerability
Vendor Patch. Secunia Advisory 3 of 7 in 2009. 1,441 views.
Release Date:
2009-07-23
Secunia Advisory ID:
SA35899
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
System access
Where:
From remote
Short Description:
A weakness and a vulnerability have been discovered in Joomla!, which can be exploited by malicious people to disclose certain system information and compromise a vulnerable system. [Read More]


Joomla! Cross-Site Scripting and Information Disclosure
Vendor Patch. Secunia Advisory 4 of 7 in 2009. 1,217 views.
Release Date:
2009-07-01
Secunia Advisory ID:
SA35668
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities and a security issue have been reported in Joomla!, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose system information. [Read More]


Joomla! Script Insertion and Cross-Site Scripting Vulnerabilities
Vendor Patch. Secunia Advisory 5 of 7 in 2009. 2,043 views.
Release Date:
2009-06-03
Secunia Advisory ID:
SA35278
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site scripting attacks. [Read More]


Joomla! Cross-Site Scripting and Cross-Site Request Forgery
Vendor Patch. Secunia Advisory 6 of 7 in 2009. 1,750 views.
Release Date:
2009-04-03
Secunia Advisory ID:
SA34551
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks. [Read More]


Joomla! "X_CMS_LIBRARY_PATH" Directory Traversal Vulnerability
Vendor Patch. Secunia Advisory 7 of 7 in 2009. 5,029 views.
Release Date:
2009-01-07
Secunia Advisory ID:
SA33377
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
Where:
From remote
Short Description:
irk4z has discovered a vulnerability in Joomla!, which can be exploited by malicious people to disclose sensitive information. [Read More]


Joomla! Script Insertion Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 7 in 2008. 3,659 views.
Release Date:
2008-11-11
Secunia Advisory ID:
SA32622
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious users and potentially malicious people to conduct script insertion attacks. [Read More]


Joomla! Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 7 in 2008. 3,913 views.
Release Date:
2008-09-10
Secunia Advisory ID:
SA31789
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Brute force
Where:
From remote
Short Description:
Some vulnerabilities and a security issue have been reported in Joomla!, where some have an unknown impact and others can potentially be exploited by malicious people to conduct brute force attacks. [Read More]


Joomla "token" Password Change Vulnerability
Vendor Patch. Secunia Advisory 3 of 7 in 2008. 12,564 views.
Release Date:
2008-08-13
Secunia Advisory ID:
SA31457
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Manipulation of data
Where:
From remote
Short Description:
d3m0n has reported a vulnerability in Joomla!, which can be exploited by malicious people to bypass certain security restrictions and manipulate data. [Read More]


Joomla Unauthorized Access Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 7 in 2008. 5,135 views.
Release Date:
2008-07-08
Secunia Advisory ID:
SA30974
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Exposure of sensitive information
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to bypass certain security restrictions and disclose potentially sensitive information. [Read More]


Joomla! "mosConfig_absolute_path" File Inclusion
Vendor Patch. Secunia Advisory 5 of 7 in 2008. 15,779 views.
Release Date:
2008-02-25
Secunia Advisory ID:
SA29106
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Hendrik-Jan Verheij has discovered a vulnerability in Joomla!, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Joomla! XML-RPC / Blogger API Vulnerability
Vendor Patch. Secunia Advisory 6 of 7 in 2008. 7,853 views.
Release Date:
2008-02-11
Secunia Advisory ID:
SA28861
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
A vulnerability has been reported in Joomla!, which can be exploited by malicious people to manipulate certain data. [Read More]


Joomla! Cross-Site Request Forgery and Script Insertion Vulnerabilities
Vendor Workaround. Secunia Advisory 7 of 7 in 2008. 8,137 views.
Release Date:
2008-01-09
Secunia Advisory ID:
SA28219
Solution Status:
Vendor Workaround
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site request forgery attacks. [Read More]


Joomla! "searchword" Cross-Site Scripting
Vendor Workaround. Secunia Advisory 1 of 3 in 2007. 11,279 views.
Release Date:
2007-10-12
Secunia Advisory ID:
SA27196
Solution Status:
Vendor Workaround
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
MustLive has discovered a vulnerability in Joomla!, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Joomla! Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 3 in 2007. 14,973 views.
Release Date:
2007-07-30
Secunia Advisory ID:
SA26239
Solution Status:
Vendor Patch
Criticality:
Impact:
Hijacking
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct session fixation attacks, cross-site scripting attacks or HTTP response splitting attacks. [Read More]


Joomla! Section Manager Script Insertion
Vendor Patch. Secunia Advisory 3 of 3 in 2007. 10,484 views.
Release Date:
2007-06-27
Secunia Advisory ID:
SA25804
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Cindy Chee has discovered a vulnerability in Joomla!, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Joomla! Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 8 in 2006. 13,910 views.
Release Date:
2006-12-29
Secunia Advisory ID:
SA23563
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Cross Site Scripting
Manipulation of data
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, where some have unknown impacts, one can be exploited by malicious people to conduct cross-site scripting attacks, and one can be exploited by malicious users to conduct SQL injection attacks. [Read More]


Joomla! Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 8 in 2006. 17,995 views.
Release Date:
2006-08-29
Secunia Advisory ID:
SA21666
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Security Bypass
Cross Site Scripting
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, where some have unknown impacts, and others can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions. [Read More]


Joomla! "id" Parameter SQL Injection Vulnerability
Vendor Patch. Secunia Advisory 3 of 8 in 2006. 12,763 views.
Release Date:
2006-08-28
Secunia Advisory ID:
SA21665
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
A vulnerability has been discovered in Joomla!, which can be exploited by malicious users to conduct SQL injection attacks. [Read More]


Joomla! Cross-Site Scripting and SQL Injection Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 8 in 2006. 14,190 views.
Release Date:
2006-06-30
Secunia Advisory ID:
SA20874
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Manipulation of data
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks. [Read More]


Joomla! "Name" SQL Injection Vulnerability
Vendor Patch. Secunia Advisory 5 of 8 in 2006. 13,254 views.
Release Date:
2006-06-19
Secunia Advisory ID:
SA20746
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
rgod has discovered a vulnerability in Joomla!, which can be exploited by malicious people to conduct SQL injection attacks. [Read More]


Joomla! Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 6 of 8 in 2006. 16,768 views.
Release Date:
2006-03-03
Secunia Advisory ID:
SA19105
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Security Bypass
Manipulation of data
Exposure of system information
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Joomla!, which can be exploited by malicious users to conduct SQL injection attacks, and by malicious people to disclose system information and potentially bypass certain security restrictions. [Read More]


Joomla! Multiple Unspecified Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 8 in 2006. 8,853 views.
Release Date:
2006-01-18
Secunia Advisory ID:
SA18513
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Where:
From remote
Short Description:
Multiple vulnerabilities with unknown impacts have been reported in Joomla!. [Read More]


Joomla! vCard Email Address Disclosure and TinyMCE Vulnerabilities
Vendor Patch. Secunia Advisory 8 of 8 in 2006. 11,021 views.
Release Date:
2006-01-09
Secunia Advisory ID:
SA18361
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Exposure of sensitive information
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose sensitive information. [Read More]


Joomla! SQL Injection and Cross-Site Scripting Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 1 in 2005. 10,138 views.
Release Date:
2005-11-22
Secunia Advisory ID:
SA17675
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Manipulation of data
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct SQL injection or cross-site scripting attacks. [Read More]