Vulnerability Database

324,311

Total vulnerabilities in the database

CVE-2015-5397

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.

  • Published: Jul 14, 2015
  • Updated: Nov 9, 2025
  • CVE: CVE-2015-5397
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
Joomla / joomla 3.4.0-rc1 3.4.0-rc1.x
Joomla / joomla 3.3.3 3.3.3.x
Joomla / joomla 3.2.1 3.2.1.x
Joomla / joomla 3.4.0-beta2 3.4.0-beta2.x
Joomla / joomla 3.4.0-alpha 3.4.0-alpha.x
Joomla / joomla 3.3.5 3.3.5.x
Joomla / joomla 3.4.1-rc2 3.4.1-rc2.x
Joomla / joomla 3.3.4 3.3.4.x
Joomla / joomla 3.3.1 3.3.1.x
Joomla / joomla 3.2.2 3.2.2.x
Joomla / joomla 3.4.1 3.4.1.x
Joomla / joomla 3.4.0-beta3 3.4.0-beta3.x
Joomla / joomla 3.4.0 3.4.0.x
Joomla / joomla 3.4.1-rc1 3.4.1-rc1.x
Joomla / joomla 3.3.0 3.3.0.x
Joomla / joomla 3.2.4 3.2.4.x
Joomla / joomla 3.2.3 3.2.3.x
Joomla / joomla 3.2.0 3.2.0.x
Joomla / joomla 3.3.2 3.3.2.x
Joomla / joomla 3.2.5 3.2.5.x
Joomla / joomla 3.4.0-beta1 3.4.0-beta1.x
Joomla / joomla 3.4.2-rc1 3.4.2-rc1.x