Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-63683
Client IP spoofing vulnerability in Regular Labs conditions manager
HIGH
CVSS 7.5
CVE-2026-63281
XSS vulnerability in Regular Labs conditions manager
MEDIUM
CVSS 4.8
CVE-2026-63280
Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager
HIGH
CVSS 8.8
CVE-2026-63265
Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints
HIGH
CVSS 8.0
CVE-2026-63264
Reflective XSS in JoomShopping < 5.9.3
MEDIUM
CVSS 5.3
CVE-2026-63048
Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2
CRITICAL
CVSS 9.4
CVE-2026-63047
Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1
HIGH
CVSS 7.5
CVE-2026-62415
Insecure default configuration Membership Pro < 4.6.2
CRITICAL
CVSS 9.1
CVE-2026-62414
Improper access control in Page Builder CK < 3.6.2
CRITICAL
CVSS 9.1
CVE-2026-61901
Open redirect in Hikashop < 6.5.2
MEDIUM
CVSS 6.1
CVE-2026-61900
Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CRITICAL
CVSS 10.0
CVE-2026-61425
Authentication bypass in Gridbox < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-61424
Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
CRITICAL
CVSS 10.0
CVE-2026-60034
Authenticated stored XSS in JMedia Extension < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-60033
SSRF via remote download in JMedia Extension < 1.6.0
MEDIUM
CVSS 5.1
CVE-2026-60032
Authenticated arbitrary file upload in JMedia < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-60031
Information disclosure in Quix Page Builder < 6.2.1
MEDIUM
CVSS 6.9
CVE-2026-60030
Broken Access Control for media management in Quix Page Builder < 6.2.1
HIGH
CVSS 8.7
CVE-2026-60029
Authenticated stored XSS in Quix Page Builder < 6.2.1
MEDIUM
CVSS 5.1
CVE-2026-60028
Authenticated stored XSS in Quix Page Builder < 6.2.1
HIGH
CVSS 8.6