Vulnerabilities
Vulnerable Software
Joomla:  >> Joomla!  >> 3.10.20  Security Vulnerabilities
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-04-01
Lack of output escaping for article titles leads to XSS vectors in various locations.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-04-01
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
CVSS Score
8.6
EPSS Score
0.0
Published
2026-04-01
An improper access check allows unauthorized access to webservice endpoints.
CVSS Score
8.6
EPSS Score
0.0
Published
2026-04-01
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
CVSS Score
6.3
EPSS Score
0.0
Published
2026-04-01
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-04-01
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-01-06
SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent.
CVSS Score
7.5
EPSS Score
0.0
Published
2015-06-18
Cross-site scripting (XSS) vulnerability in manage.php in the PBBooking (com_pbbooking) component 2.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the an arbitrary parameter in an edit action to administrator/index.php.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-03-19
Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) calid or (2) paletteDefault parameter in an editevent action to index.php.
CVSS Score
4.3
EPSS Score
0.004
Published
2014-03-19


Contact Us

Shodan ® - All rights reserved