Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-77990
Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1
MEDIUM
CVSS 5.3
CVE-2026-77989
Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1
MEDIUM
CVSS 5.3
CVE-2026-77035
Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1
MEDIUM
CVSS 5.1
CVE-2026-77034
Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1
MEDIUM
CVSS 6.9
CVE-2026-77997
Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41
MEDIUM
CVSS 5.1
CVE-2026-77993
Reflected XSS in Page Builder CK < 3.6.5
MEDIUM
CVSS 5.3
CVE-2026-76609
Unauthenticated modification of any comment in Fabrik < 4.7.2
MEDIUM
CVSS 6.9
CVE-2026-76608
Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2
MEDIUM
CVSS 6.9
CVE-2026-76603
Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2
MEDIUM
CVSS 6.9
CVE-2026-76601
Unauthenticated row reordering in Fabrik < 4.7.2
MEDIUM
CVSS 6.9
CVE-2026-76600
Unauthenticated deletion of any comment in Fabrik < 4.7.2
MEDIUM
CVSS 6.9
CVE-2026-66916
Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctly enforces the password gate
MEDIUM
CVSS 6.9
CVE-2026-67362
Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 5.1
CVE-2026-67361
Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 6.9
CVE-2026-67360
Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 6.3
CVE-2026-67358
Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 5.3
CVE-2026-77028
Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
MEDIUM
CVSS 5.3
CVE-2026-76611
Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
MEDIUM
CVSS 6.9
CVE-2026-77029
Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
MEDIUM
CVSS 4.6
CVE-2026-77026
Client-controlled validation bypass in Convert Forms extension < 5.2.5
MEDIUM
CVSS 6.9