Vulnerability Database

314,343

Total vulnerabilities in the database

CVE-2015-5397

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.

  • Published: Jul 14, 2015
  • Updated: Nov 9, 2025
  • CVE: CVE-2015-5397
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
Joomla / joomla 3.4.0-rc1 3.4.0-rc1.x
Joomla / joomla 3.3.3 3.3.3.x
Joomla / joomla 3.2.1 3.2.1.x
Joomla / joomla 3.4.0-beta2 3.4.0-beta2.x
Joomla / joomla 3.4.0-alpha 3.4.0-alpha.x
Joomla / joomla 3.3.5 3.3.5.x
Joomla / joomla 3.4.1-rc2 3.4.1-rc2.x
Joomla / joomla 3.3.4 3.3.4.x
Joomla / joomla 3.3.1 3.3.1.x
Joomla / joomla 3.2.2 3.2.2.x
Joomla / joomla 3.4.1 3.4.1.x
Joomla / joomla 3.4.0-beta3 3.4.0-beta3.x
Joomla / joomla 3.4.0 3.4.0.x
Joomla / joomla 3.4.1-rc1 3.4.1-rc1.x
Joomla / joomla 3.3.0 3.3.0.x
Joomla / joomla 3.2.4 3.2.4.x
Joomla / joomla 3.2.3 3.2.3.x
Joomla / joomla 3.2.0 3.2.0.x
Joomla / joomla 3.3.2 3.3.2.x
Joomla / joomla 3.2.5 3.2.5.x
Joomla / joomla 3.4.0-beta1 3.4.0-beta1.x
Joomla / joomla 3.4.2-rc1 3.4.2-rc1.x