Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1213 résultats

CVE-2026-81565 Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-81564 Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.0 CVE-2026-79700 Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-78375 Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 com_content · 1 source · HIGH CVSS 8.6 CVE-2026-88853 Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 Modals · 1 source · HIGH CVSS 7.5 CVE-2026-88852 Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 Snippets (Free) · 1 source · HIGH CVSS 7.5 CVE-2026-85196 Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 Articles Anywhere · 1 source · MEDIUM CVSS 5.3 CVE-2026-85195 Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 Articles Anywhere (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85192 Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 Conditional Content Pro · 1 source · CRITICAL CVSS 9.4 CVE-2026-85191 Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 Tabs & Accordions (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85190 Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 Quick Index (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85189 Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 Modals (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85188 Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla Advanced Module Manager (Free, Pro) · 1 source · MEDIUM CVSS 6.9 CVE-2026-78085 Path Traversal in Gallery Image Management in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-78374 Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 Extension Joomla — joomlart.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-78303 Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-78302 Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.6 CVE-2026-78084 Missing Access Control in Gallery Image Management in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-78083 Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.1 CVE-2026-78082 Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · CRITICAL CVSS 9.3