Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

642 résultats

CVE-2026-75115 Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 Extension Joomla — yootheme.com · 1 source · HIGH CVSS 7.0 CVE-2026-76564 Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 Extension Joomla — phoca.cz · 1 source · HIGH CVSS 8.6 CVE-2026-75948 Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 Extension Joomla — icagenda.com · 1 source · HIGH CVSS 8.6 CVE-2026-75956 DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · HIGH CVSS 8.7 CVE-2026-75953 Open mail relay in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · HIGH CVSS 7.5 CVE-2026-67363 Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 Balbooa Forms · 1 source · HIGH CVSS 7.7 CVE-2026-71571 Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 Extension Joomla — icagenda.com · 1 source · HIGH CVSS 8.6 CVE-2026-66494 Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.7 CVE-2026-66491 Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 Extension Joomla — phoca.cz · 1 source · HIGH CVSS 8.2 CVE-2026-65947 Various CSRF vectors in the admin interface in Gridbox < 2.20.2 Gridbox · 1 source · HIGH CVSS 7.3 CVE-2026-65944 CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 ro_csvi · 1 source · HIGH CVSS 8.8 CVE-2026-65943 Unauthenticated directory creation RO CSVI < 9.11.0 ro_csvi · 1 source · HIGH CVSS 7.5 CVE-2026-65881 Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 Joomdle · 1 source · HIGH CVSS 7.5 CVE-2026-65878 Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.3 CVE-2026-65877 Authenticated SQL injection in SP Page Builder < 6.7.1 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.2 CVE-2026-65759 unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.7 CVE-2026-65758 Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 Extension Joomla — tassos.gr · 1 source · HIGH CVSS 8.2 CVE-2026-65757 Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.1 CVE-2026-65755 Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-65754 Insecure path handling in ReReplacer Pro extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5