Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

585 résultats

CVE-2026-77990 Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 Extension Joomla — joomlaeventmanager.net · 1 source · MEDIUM CVSS 5.3 CVE-2026-77989 Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 Extension Joomla — joomlaeventmanager.net · 1 source · MEDIUM CVSS 5.3 CVE-2026-77035 Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 Extension Joomla — joomlaeventmanager.net · 1 source · MEDIUM CVSS 5.1 CVE-2026-77034 Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 Extension Joomla — joomlaeventmanager.net · 1 source · MEDIUM CVSS 6.9 CVE-2026-77997 Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 com_template · 1 source · MEDIUM CVSS 5.1 CVE-2026-77993 Reflected XSS in Page Builder CK < 3.6.5 Extension Joomla — joomlack.fr · 1 source · MEDIUM CVSS 5.3 CVE-2026-76609 Unauthenticated modification of any comment in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-76608 Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-76603 Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-76601 Unauthenticated row reordering in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-76600 Unauthenticated deletion of any comment in Fabrik < 4.7.2 Extension Joomla — fabrikar.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-66916 Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctly enforces the password gate Extension Joomla — joomgalleryfriends.net · 1 source · MEDIUM CVSS 6.9 CVE-2026-67362 Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 Extension Joomla — j2commerce.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-67361 Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 Extension Joomla — j2commerce.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-67360 Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 Extension Joomla — j2commerce.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67358 Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 Extension Joomla — j2commerce.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-77028 Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-76611 Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-77029 Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 4.6 CVE-2026-77026 Client-controlled validation bypass in Convert Forms extension < 5.2.5 Extension Joomla — tassos.gr · 1 source · MEDIUM CVSS 6.9