Veille sécurité Joomla
Dernière synchronisation · mise à jour automatique toutes les 60 min
Critiques récentesTout voir
CVE-2026-88857
Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.4
CVE-2026-88856
Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.4
CVE-2026-88854
Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.3
CVE-2026-85192
Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0
CRITICAL
CVSS 9.4
CVE-2026-78082
Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4
CRITICAL
CVSS 9.3
Dernières vulnérabilitésTout voir
CVE-2026-90905
Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 7.2
CVE-2026-90904
Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90903
Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 7.2
CVE-2026-90902
Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90901
Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90900
Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0
MEDIUM
CVSS 5.3
CVE-2026-90899
Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.2
CVE-2026-88857
Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.4
CVE-2026-88856
Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.4
CVE-2026-88855
Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
HIGH
CVSS 8.6
CVE-2026-88854
Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.3
CVE-2026-84048
Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2
MEDIUM
CVSS 6.3
SourcesStatut
Joomla Security Centre
OK
NVD
OK
OSV
OK
GitHub Advisories
OK
CERT-FR (ANSSI)
OK