Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-81565
Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0
MEDIUM
CVSS 6.9
CVE-2026-81564
Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0
HIGH
CVSS 7.0
CVE-2026-79700
Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4
MEDIUM
CVSS 6.9
CVE-2026-78375
Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1
HIGH
CVSS 8.6
CVE-2026-88853
Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0
HIGH
CVSS 7.5
CVE-2026-88852
Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0
HIGH
CVSS 7.5
CVE-2026-85196
Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0
MEDIUM
CVSS 5.3
CVE-2026-85195
Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0
HIGH
CVSS 7.5
CVE-2026-85192
Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0
CRITICAL
CVSS 9.4
CVE-2026-85191
Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0
HIGH
CVSS 7.5
CVE-2026-85190
Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5
HIGH
CVSS 7.5
CVE-2026-85189
Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0
HIGH
CVSS 7.5
CVE-2026-85188
Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla
MEDIUM
CVSS 6.9
CVE-2026-78085
Path Traversal in Gallery Image Management in SP Property < 4.1.4
MEDIUM
CVSS 6.9
CVE-2026-78374
Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0
MEDIUM
CVSS 6.9
CVE-2026-78303
Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4
MEDIUM
CVSS 6.9
CVE-2026-78302
Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4
HIGH
CVSS 8.6
CVE-2026-78084
Missing Access Control in Gallery Image Management in SP Property < 4.1.4
MEDIUM
CVSS 6.9
CVE-2026-78083
Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4
HIGH
CVSS 7.1
CVE-2026-78082
Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4
CRITICAL
CVSS 9.3