CVE-2021-26036 – [20210702] - Core - DoS through usergroup table manipulation
https://notcve.org/view.php?id=CVE-2021-26036
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table. Se ha detectado un problema en Joomla! versiones 2.5.0 hasta 3.9.27. • https://developer.joomla.org/security-centre/857-20210702-core-dos-through-usergroup-table-manipulation.html • CWE-20: Improper Input Validation •
CVE-2021-26029 – [20210309] - Core - Inadequate filtering of form contents could allow to overwrite the author field
https://notcve.org/view.php?id=CVE-2021-26029
An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field. Se detectó un problema en Joomla! versiones 1.6.0 hasta 3.9.24. • https://developer.joomla.org/security-centre/849-20210309-core-inadequate-filtering-of-form-contents-could-allow-to-overwrite-the-author-field.html •
CVE-2021-23130 – [20210304] - Core - XSS within the feed parser library
https://notcve.org/view.php?id=CVE-2021-23130
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. Se detectó un problema en Joomla! versiones 2.5.0 hasta 3.9.24. • https://developer.joomla.org/security-centre/844-20210304-core-xss-within-the-feed-parser-library.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-23129 – [20210303] - Core - XSS within alert messages showed to users
https://notcve.org/view.php?id=CVE-2021-23129
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues. Se detectó un problema en Joomla! versiones 2.5.0 hasta 3.9.24. • https://developer.joomla.org/security-centre/843-20210303-core-xss-within-alert-messages-showed-to-users.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-35616 – [20201107] - Core - Write ACL violation in multiple core views
https://notcve.org/view.php?id=CVE-2020-35616
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. Se detectó un problema en Joomla! versiones 1.7.0 hasta 3.9.22. • https://developer.joomla.org/security-centre/834-20201107-core-write-acl-violation-in-multiple-core-views.html • CWE-20: Improper Input Validation •