Exposição de Joomla

CMS
986
score de exposição
94.953
sites usam
4
em exploração
58
críticos
Análise Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

332 resultados
CVE-2023-28731CRITICALUnauthenticated RCE affecting the AcyMailing plugin for JoomlaEPSS 1.8%CVE-2013-3932SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "BusineEPSS 1.8%CVE-2020-35612[20201103] - Core - Path traversal in mod_random_imageEPSS 1.6%CVE-2011-4937Joomla! 1.7.1 has core information disclosure due to inadequate error checking.EPSS 1.6%CVE-2020-35610[20201101] - Core - com_finder ignores access levels on autosuggestEPSS 1.3%CVE-2021-23127[20210301] - Core - Insecure randomness within 2FA secret generationEPSS 1.3%CVE-2021-23128[20210302] - Core - Potential Insecure FOFEncryptRandvalEPSS 1.3%CVE-2020-35611[20201102] - Core - Disclosure of secrets in Global Configuration pageEPSS 1.3%CVE-2021-23131[20210305] - Core - Input validation within the template managerEPSS 1.3%CVE-2021-26036[20210702] - Core - DoS through usergroup table manipulationEPSS 1.2%CVE-2022-23799[20220307] - Core - Variable Tampering on JInput $_REQUEST dataEPSS 1.2%CVE-2017-2550Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.EPSS 1.2%CVE-2021-23123[20210101] - Core - com_modules exposes module namesEPSS 1.2%CVE-2011-3629Joomla! core 1.7.1 allows information disclosure due to weak encryptionEPSS 1.1%CVE-2022-23795[20220303] - Core - User row are not bound to a authentication mechanismEPSS 1.1%CVE-2010-1433Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-suEPSS 1.1%CVE-2010-1435Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions EPSS 1.1%CVE-2022-23797[20220305] - Core - Inadequate filtering on the selected IdsEPSS 1.1%CVE-2021-23126[20210301] - Core - Insecure randomness within 2FA secret generationEPSS 1.1%CVE-2020-35614[20201105] - Core - User Enumeration in backend loginEPSS 1.1%