Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

194 résultats

CVE-2026-74804 Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 Extension Joomla — yootheme.com · 1 source · CRITICAL CVSS 9.3 CVE-2026-74803 Unauthenticated arbitrary file upload in Zoo < 4.1.64 Extension Joomla — yootheme.com · 1 source · CRITICAL CVSS 10.0 CVE-2026-67364 Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 Balbooa Forms · 1 source · CRITICAL CVSS 10.0 CVE-2026-74254 SQL injection in Page Builder CK < 3.6.5 Extension Joomla — joomlack.fr · 1 source · CRITICAL CVSS 9.3 CVE-2026-74253 Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 Extension Joomla — regularlabs.com · 1 source · CRITICAL CVSS 10.0 CVE-2026-74251 Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 Extension Joomla — phoca.cz · 1 source · CRITICAL CVSS 9.3 CVE-2026-67365 Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 mod_icagenda_calendar · 1 source · CRITICAL CVSS 9.2 CVE-2026-67285 Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · CRITICAL CVSS 9.2 CVE-2026-67282 Unauthenticated remote code execution in Fabrik < 4.6.8 Extension Joomla — fabrikar.com · 1 source · CRITICAL CVSS 10.0 CVE-2026-66915 Remote code execution in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · CRITICAL CVSS 10.0 CVE-2026-66914 Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 Extension Joomla — seblod.com · 1 source · CRITICAL CVSS 9.2 CVE-2026-65888 Account takeover vulnerability in Gridbox < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 10.0 CVE-2026-65887 Unauthenticated arbitrary password reset in Gridbox < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 10.0 CVE-2026-65886 Unauthenticated arbitrary file read in Gridbox < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 9.2 CVE-2026-65890 Unauthenticated SQL injection in Gridbox < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 9.2 CVE-2026-65889 Unauthenticated recursive directory deletion < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 9.2 CVE-2026-65885 Authenticated arbitrary file upload in Gridbox < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 9.4 CVE-2026-65884 Privilege Escalation in Gridbox < 2.20.2 Gridbox · 1 source · CRITICAL CVSS 10.0 CVE-2026-65883 RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 Aimy Captcha-Less Form Guard · 1 source · CRITICAL CVSS 10.0 CVE-2026-65880 Unauthenticated remote code execution in Balbooa Forms < 2.4.3 Balbooa Forms · 1 source · CRITICAL CVSS 10.0