![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-27912 – [20221001] - Core - Debug Mode leaks full request payloads including passwords
https://notcve.org/view.php?id=CVE-2022-27912
25 Oct 2022 — An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. Se ha detectado un problema en Joomla! versiones 4.0.0 hasta 4.2.3. • https://developer.joomla.org/security-centre/885-20221001-core-disclosure-of-critical-information-in-debug-mode.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-27911 – [20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check'
https://notcve.org/view.php?id=CVE-2022-27911
31 Aug 2022 — An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. Se ha detectado un problema en Joomla! Versión 4.2.0. • https://developer.joomla.org/security-centre/884-20220801-core-multiple-full-path-disclosures-because-of-missing-jexec-or-die-check.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23801 – [20220309] - Core - XSS attack vector through SVG
https://notcve.org/view.php?id=CVE-2022-23801
30 Mar 2022 — An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media. Se ha detectado un problema en Joomla! versiones 4.0.0 hasta 4.1.0. • https://developer.joomla.org/security-centre/878-20220309-core-xss-attack-vector-through-svg.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23800 – [20220308] - Core - Inadequate content filtering within the filter code
https://notcve.org/view.php?id=CVE-2022-23800
30 Mar 2022 — An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Se ha detectado un problema en Joomla! versiones 4.0.0 hasta 4.1.0. • https://developer.joomla.org/security-centre/877-20220308-core-inadequate-content-filtering-within-the-filter-code.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23799 – [20220307] - Core - Variable Tampering on JInput $_REQUEST data
https://notcve.org/view.php?id=CVE-2022-23799
30 Mar 2022 — An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data. Se ha detectado un problema en Joomla! Versiones 4.0.0 hasta 4.1.0. • https://developer.joomla.org/security-centre/876-20220307-core-variable-tampering-on-jinput-request-data.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23798 – [20220306] - Core - Inadequate validation of internal URLs
https://notcve.org/view.php?id=CVE-2022-23798
30 Mar 2022 — An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. Se ha detectado un problema en Joomla! Versiones 2.5.0 hasta 3.10.6 y 4.0.0 hasta 4.1.0. • https://developer.joomla.org/security-centre/875-20220306-core-inadequate-validation-of-internal-urls.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23797 – [20220305] - Core - Inadequate filtering on the selected Ids
https://notcve.org/view.php?id=CVE-2022-23797
30 Mar 2022 — An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection. Se ha detectado un problema en Joomla! versiones 3.0.0 hasta 3.10.6 y 4.0.0 hasta 4.1.0. • https://developer.joomla.org/security-centre/874-20220305-core-inadequate-filtering-on-the-selected-ids.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23795 – [20220303] - Core - User row are not bound to a authentication mechanism
https://notcve.org/view.php?id=CVE-2022-23795
30 Mar 2022 — An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover. Se ha detectado un problema en Joomla! versiones 2.5.0 hasta 3.10.6 y 4.0.0 hasta 4.1.0. • https://developer.joomla.org/security-centre/872-20220303-core-user-row-are-not-bound-to-a-authentication-mechanism.html • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23794 – [20220302] - Core - Path Disclosure within filesystem error messages
https://notcve.org/view.php?id=CVE-2022-23794
30 Mar 2022 — An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application. Se ha detectado un problema en Joomla! • https://developer.joomla.org/security-centre/871-20220302-core-path-disclosure-within-filesystem-error-messages.html • CWE-209: Generation of Error Message Containing Sensitive Information •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-23793 – [20220301] - Core - Zip Slip within the Tar extractor
https://notcve.org/view.php?id=CVE-2022-23793
30 Mar 2022 — An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. Se ha detectado un problema en Joomla! versiones 3.0.0 hasta 3.10.6 y 4.0.0 hasta 4.1.0. • https://packetstorm.news/files/id/166546 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •