Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-90905
Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 7.2
CVE-2026-90904
Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90903
Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 7.2
CVE-2026-90902
Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90901
Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90900
Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0
MEDIUM
CVSS 5.3
CVE-2026-90899
Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.2
CVE-2026-88857
Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.4
CVE-2026-88856
Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.4
CVE-2026-88855
Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
HIGH
CVSS 8.6
CVE-2026-88854
Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
CRITICAL
CVSS 9.3
CVE-2026-84048
Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2
MEDIUM
CVSS 6.3
CVE-2026-82191
Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
MEDIUM
CVSS 5.3
CVE-2026-82190
Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
MEDIUM
CVSS 6.3
CVE-2026-82189
Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 8.7
CVE-2026-81568
Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 8.7
CVE-2026-81567
Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 8.7
CVE-2026-78081
Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 7.1
CVE-2026-79701
Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6
MEDIUM
CVSS 6.9
CVE-2026-81566
Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0
MEDIUM
CVSS 5.1