Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-23899
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2026-21631
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2026-21627
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point.
CRITICAL
CVSS 9.5
CVE-2026-21625
User provided uploads to the Easy Discuss component for Joomla aren't properly validated.
MEDIUM
CVSS 4.8
CVE-2026-21624
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
CRITICAL
CVSS 9.4
CVE-2026-21623
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
CRITICAL
CVSS 9.4
CVE-2025-63082
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2025-63083
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2025-55758
Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.
MEDIUM
CVSS 5.4
CVE-2025-55757
A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.
MEDIUM
CVSS 6.1
CVE-2025-40636
SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3.
CRITICAL
CVSS 9.3
CVE-2025-54477
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2025-54476
Multiples vulnérabilités dans Joomla!
UNKNOWN
CVE-2025-54301
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-54300
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-54475
A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.
HIGH
CVSS 8.7
CVE-2025-54474
A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered.
HIGH
CVSS 8.5
CVE-2025-54473
An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered.
CRITICAL
CVSS 9.2
CVE-2025-54299
A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.
CRITICAL
CVSS 9.4
CVE-2025-54298
A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.
CRITICAL
CVSS 9.4