Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

642 résultats

CVE-2026-78083 Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.1 CVE-2026-78065 Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 7.1 CVE-2026-78064 Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.8 CVE-2026-77999 Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-78078 Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.9 CVE-2026-78077 Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.6 CVE-2026-78074 Unauthenticated arbitrary extension deinstallation via various miniOrange extensions Extension Joomla — miniorgange.com · 1 source · HIGH CVSS 8.8 CVE-2026-78072 Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1 Extension Joomla — Jefferson49 · 1 source · HIGH CVSS 8.7 CVE-2026-78071 Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 Extension Joomla — digital-peak.com · 1 source · HIGH CVSS 7.5 CVE-2026-77996 Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 Extension Joomla — yootheme.com · 1 source · HIGH CVSS 7.5 CVE-2026-77027 Unauthenticated stored XSS in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · HIGH CVSS 8.6 CVE-2026-76599 Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · HIGH CVSS 8.7 CVE-2026-76598 Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · HIGH CVSS 8.7 CVE-2026-76597 Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · HIGH CVSS 8.7 CVE-2026-76596 Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table Extension Joomla — fabrikar.com · 1 source · HIGH CVSS 8.7 CVE-2026-66917 Stored XSS in JoomGallery < 4.4.0 Extension Joomla — joomgalleryfriends.net · 1 source · HIGH CVSS 8.6 CVE-2026-74252 Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.6 CVE-2026-67359 Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-76613 Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 Extension Joomla — yootheme.com · 1 source · HIGH CVSS 8.6 CVE-2026-76612 Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 Extension Joomla — yootheme.com · 1 source · HIGH CVSS 8.6