Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1619 résultats

CVE-2026-57831 Unauthenticated blind SQL injection in DP Calendar 8.18.0 Extension Joomla — digital-peak.com · 1 source · HIGH CVSS 8.7 CVE-2026-57830 Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 helix_ultimate · 1 source · HIGH CVSS 8.8 CVE-2026-57829 Unauthenticated stored XSS in Helix Ultimate < 2.2.7 helix_ultimate · 1 source · HIGH CVSS 8.7 CVE-2026-57828 Authenticated file upload in Phoca Downloads component < 6.1.3 download · 1 source · CRITICAL CVSS 9.0 CVE-2026-57827 Unauthenticated file upload in RSFiles component < 1.17.12 rsfiles! · 1 source · CRITICAL CVSS 10.0 CVE-2026-56292 SQL Injection in AcyMailing extension < 10.11.1 acymailing · 1 source · CRITICAL CVSS 9.2 CVE-2026-56291 Unauthenticated file upload in Balbooa Forms extension < 2.4.1 forms · 1 source · CRITICAL CVSS 10.0 CVE-2026-48947 Incorrect Access Control in com_media webservice endpoints Joomla CMS · 2 sources · LOW CVE-2026-48948 Incorrect Access Control in com_contact vcf download Joomla CMS · 2 sources · LOW CVE-2026-48949 XSS in MFA method management Joomla CMS · 2 sources · MEDIUM CVE-2026-48950 XSS in com_templates Joomla CMS · 2 sources · MEDIUM CVE-2026-48951 XSS in various modalreturn layouts Joomla CMS · 2 sources · MEDIUM CVE-2026-48952 XSS in com_installer Joomla CMS · 2 sources · MEDIUM CVE-2026-48953 XSS in the generic image output layout Joomla CMS · 2 sources · MEDIUM CVE-2026-48954 XSS through language overrides Joomla CMS · 2 sources · MEDIUM CVE-2026-48955 Incorrect Access Control in com_workflow Joomla CMS · 2 sources · MEDIUM CVE-2026-48956 Incorrect Access Control in com_modules Joomla CMS · 2 sources · MEDIUM CVE-2026-48957 Incorrect Access Control in com_privacy webservice endpoints Joomla CMS · 2 sources · MEDIUM CVE-2026-48958 Incorrect Access Control in com_fields webservice endpoints Joomla CMS · 2 sources · MEDIUM CVE-2026-56290 Unauthenticated file upload in Page Builder CK extension < 3.6.0 page_builder_ck · 1 source · CRITICAL CVSS 10.0