Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-60027
Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1
HIGH
CVSS 8.7
CVE-2026-60026
Authenticated PHP code execution in Quix Page Builder < 6.2.1
HIGH
CVSS 8.9
CVE-2026-60025
User enumeration in Events Booking < 5.8.0
HIGH
CVSS 8.8
CVE-2026-60024
Insecure default configuration Events Booking < 5.8.0
CRITICAL
CVSS 9.8
CVE-2026-58149
User enumeration in Events Booking < 5.8.0
MEDIUM
CVSS 5.3
CVE-2026-58148
Stored XSS in ChronoForms extension for Joomla 8.0
HIGH
CVSS 8.7
CVE-2026-58078
Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1
HIGH
CVSS 8.7
CVE-2026-58077
Unauthenticated stored XSS in 4Analytics < 5.0.2
HIGH
CVSS 8.7
CVE-2026-57833
Unauthenticated stored XSS in 4Analytics < 5.0.2
HIGH
CVSS 8.6
CVE-2026-57832
Unauthenticated blind SQL injection in EDocman < 3.9
HIGH
CVSS 8.7
CVE-2026-57831
Unauthenticated blind SQL injection in DP Calendar 8.18.0
HIGH
CVSS 8.7
CVE-2026-57830
Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7
HIGH
CVSS 8.8
CVE-2026-57829
Unauthenticated stored XSS in Helix Ultimate < 2.2.7
HIGH
CVSS 8.7
CVE-2026-57828
Authenticated file upload in Phoca Downloads component < 6.1.3
CRITICAL
CVSS 9.0
CVE-2026-57827
Unauthenticated file upload in RSFiles component < 1.17.12
CRITICAL
CVSS 10.0
CVE-2026-56292
SQL Injection in AcyMailing extension < 10.11.1
CRITICAL
CVSS 9.2
CVE-2026-56291
Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CRITICAL
CVSS 10.0
CVE-2026-56290
Unauthenticated file upload in Page Builder CK extension < 3.6.0
CRITICAL
CVSS 10.0
CVE-2026-49049
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and upda…
HIGH
CVSS 7.5
CVE-2026-49048
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter in…
HIGH
CVSS 8.7