Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-74804
Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64
CRITICAL
CVSS 9.3
CVE-2026-74803
Unauthenticated arbitrary file upload in Zoo < 4.1.64
CRITICAL
CVSS 10.0
CVE-2026-67364
Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2
CRITICAL
CVSS 10.0
CVE-2026-74254
SQL injection in Page Builder CK < 3.6.5
CRITICAL
CVSS 9.3
CVE-2026-74253
Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0
CRITICAL
CVSS 10.0
CVE-2026-74251
Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
CRITICAL
CVSS 9.3
CVE-2026-67365
Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11
CRITICAL
CVSS 9.2
CVE-2026-67285
Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0
CRITICAL
CVSS 9.2
CVE-2026-67282
Unauthenticated remote code execution in Fabrik < 4.6.8
CRITICAL
CVSS 10.0
CVE-2026-66915
Remote code execution in Fabrik < 4.7.2
CRITICAL
CVSS 10.0
CVE-2026-66914
Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1
CRITICAL
CVSS 9.2
CVE-2026-65888
Account takeover vulnerability in Gridbox < 2.20.2
CRITICAL
CVSS 10.0
CVE-2026-65887
Unauthenticated arbitrary password reset in Gridbox < 2.20.2
CRITICAL
CVSS 10.0
CVE-2026-65886
Unauthenticated arbitrary file read in Gridbox < 2.20.2
CRITICAL
CVSS 9.2
CVE-2026-65890
Unauthenticated SQL injection in Gridbox < 2.20.2
CRITICAL
CVSS 9.2
CVE-2026-65889
Unauthenticated recursive directory deletion < 2.20.2
CRITICAL
CVSS 9.2
CVE-2026-65885
Authenticated arbitrary file upload in Gridbox < 2.20.2
CRITICAL
CVSS 9.4
CVE-2026-65884
Privilege Escalation in Gridbox < 2.20.2
CRITICAL
CVSS 10.0
CVE-2026-65883
RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0
CRITICAL
CVSS 10.0
CVE-2026-65880
Unauthenticated remote code execution in Balbooa Forms < 2.4.3
CRITICAL
CVSS 10.0