Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-61900
Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CRITICAL
CVSS 10.0
CVE-2026-61425
Authentication bypass in Gridbox < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-61424
Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
CRITICAL
CVSS 10.0
CVE-2026-60034
Authenticated stored XSS in JMedia Extension < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-60033
SSRF via remote download in JMedia Extension < 1.6.0
MEDIUM
CVSS 5.1
CVE-2026-60032
Authenticated arbitrary file upload in JMedia < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-60031
Information disclosure in Quix Page Builder < 6.2.1
MEDIUM
CVSS 6.9
CVE-2026-60030
Broken Access Control for media management in Quix Page Builder < 6.2.1
HIGH
CVSS 8.7
CVE-2026-60029
Authenticated stored XSS in Quix Page Builder < 6.2.1
MEDIUM
CVSS 5.1
CVE-2026-60028
Authenticated stored XSS in Quix Page Builder < 6.2.1
HIGH
CVSS 8.6
CVE-2026-60027
Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1
HIGH
CVSS 8.7
CVE-2026-60026
Authenticated PHP code execution in Quix Page Builder < 6.2.1
HIGH
CVSS 8.9
CVE-2026-60025
User enumeration in Events Booking < 5.8.0
HIGH
CVSS 8.8
CVE-2026-60024
Insecure default configuration Events Booking < 5.8.0
CRITICAL
CVSS 9.8
CVE-2026-58149
User enumeration in Events Booking < 5.8.0
MEDIUM
CVSS 5.3
CVE-2026-58148
Stored XSS in ChronoForms extension for Joomla 8.0
HIGH
CVSS 8.7
CVE-2026-58078
Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1
HIGH
CVSS 8.7
CVE-2026-58077
Unauthenticated stored XSS in 4Analytics < 5.0.2
HIGH
CVSS 8.7
CVE-2026-57833
Unauthenticated stored XSS in 4Analytics < 5.0.2
HIGH
CVSS 8.6
CVE-2026-57832
Unauthenticated blind SQL injection in EDocman < 3.9
HIGH
CVSS 8.7