Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-78080
Unauthenticated SQL injection in JooDatabase Lite < 5.1.0
CRITICAL
CVSS 9.3
CVE-2026-78069
Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
CRITICAL
CVSS 9.5
CVE-2026-78065
Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
HIGH
CVSS 7.1
CVE-2026-78064
Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
HIGH
CVSS 8.8
CVE-2026-78000
Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
MEDIUM
CVSS 5.3
CVE-2026-77999
Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
HIGH
CVSS 8.7
CVE-2026-78079
Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10
MEDIUM
CVSS 5.3
CVE-2026-78078
Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10
HIGH
CVSS 8.9
CVE-2026-78077
Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10
HIGH
CVSS 8.6
CVE-2026-78076
Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10
MEDIUM
CVSS 5.1
CVE-2026-78075
Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10
MEDIUM
CVSS 5.1
CVE-2026-78074
Unauthenticated arbitrary extension deinstallation via various miniOrange extensions
HIGH
CVSS 8.8
CVE-2026-78073
Reflected XSS in All Video Share 1.0.0-4.5.0
MEDIUM
CVSS 5.3
CVE-2026-78072
Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
HIGH
CVSS 8.7
CVE-2026-78071
Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0
HIGH
CVSS 7.5
CVE-2026-78070
Authenticated, privileged blind SQL injection in DP Calendar 5.5.0
MEDIUM
CVSS 6.9
CVE-2026-77991
Privileged remote code execution in Joomla Event Manager < 5.0.1
CRITICAL
CVSS 9.4
CVE-2026-77990
Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1
MEDIUM
CVSS 5.3
CVE-2026-77989
Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1
MEDIUM
CVSS 5.3
CVE-2026-77035
Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1
MEDIUM
CVSS 5.1