Veille

Veille sécurité Joomla

Dernière synchronisation · mise à jour automatique toutes les 60 min

Critical2177 sur 30 jours High750585 moyennes · 16 faibles Joomla Core399Joomla CMS Extensions121356 au total sur 30 jours
CVE-2026-90905 Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 7.2 CVE-2026-90904 Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.6 CVE-2026-90903 Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.2 CVE-2026-90902 Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 8.6 CVE-2026-90901 Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 8.6 CVE-2026-90900 Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · MEDIUM CVSS 5.3 CVE-2026-90899 Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.2 CVE-2026-88857 Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · CRITICAL CVSS 9.4 CVE-2026-88856 Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · CRITICAL CVSS 9.4 CVE-2026-88855 Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · HIGH CVSS 8.6 CVE-2026-88854 Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · CRITICAL CVSS 9.3 CVE-2026-84048 Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 Extension Joomla — joomgalleryfriends.net · 1 source · MEDIUM CVSS 6.3
Joomla Security Centre
OK
NVD
OK
OSV
OK
GitHub Advisories
OK
CERT-FR (ANSSI)
OK