Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-57831
Unauthenticated blind SQL injection in DP Calendar 8.18.0
HIGH
CVSS 8.7
CVE-2026-57830
Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7
HIGH
CVSS 8.8
CVE-2026-57829
Unauthenticated stored XSS in Helix Ultimate < 2.2.7
HIGH
CVSS 8.7
CVE-2026-57828
Authenticated file upload in Phoca Downloads component < 6.1.3
CRITICAL
CVSS 9.0
CVE-2026-57827
Unauthenticated file upload in RSFiles component < 1.17.12
CRITICAL
CVSS 10.0
CVE-2026-56292
SQL Injection in AcyMailing extension < 10.11.1
CRITICAL
CVSS 9.2
CVE-2026-56291
Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CRITICAL
CVSS 10.0
CVE-2026-48947
Incorrect Access Control in com_media webservice endpoints
LOW
CVE-2026-48948
Incorrect Access Control in com_contact vcf download
LOW
CVE-2026-48949
XSS in MFA method management
MEDIUM
CVE-2026-48950
XSS in com_templates
MEDIUM
CVE-2026-48951
XSS in various modalreturn layouts
MEDIUM
CVE-2026-48952
XSS in com_installer
MEDIUM
CVE-2026-48953
XSS in the generic image output layout
MEDIUM
CVE-2026-48954
XSS through language overrides
MEDIUM
CVE-2026-48955
Incorrect Access Control in com_workflow
MEDIUM
CVE-2026-48956
Incorrect Access Control in com_modules
MEDIUM
CVE-2026-48957
Incorrect Access Control in com_privacy webservice endpoints
MEDIUM
CVE-2026-48958
Incorrect Access Control in com_fields webservice endpoints
MEDIUM
CVE-2026-56290
Unauthenticated file upload in Page Builder CK extension < 3.6.0
CRITICAL
CVSS 10.0