Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

368 résultats

CVE-2026-76610 Unauthenticated tag modifications in Zoo < 4.1.65 Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-76569 Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 Extension Joomla — phoca.cz · 1 source · MEDIUM CVSS 5.3 CVE-2026-76565 Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 Extension Joomla — phoca.cz · 1 source · MEDIUM CVSS 5.3 CVE-2026-75955 Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-75952 Cross-site request forgery in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 4.6 CVE-2026-75951 Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-75950 Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-75114 Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-71570 ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 com_icagenda · 1 source · MEDIUM CVSS 5.1 CVE-2026-67366 CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 Extension Joomla — icagenda.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-67287 Unauthenticated comment creation in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67286 Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67284 Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 Extension Joomla — tabaoca.org · 1 source · MEDIUM CVSS 5.3 CVE-2026-67283 Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 Extension Joomla — tabaoca.org · 1 source · MEDIUM CVSS 6.9 CVE-2026-66493 Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 Extension Joomla — phoca.cz · 1 source · MEDIUM CVSS 6.4 CVE-2026-66492 Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 Extension Joomla — phoca.cz · 1 source · MEDIUM CVSS 6.1 CVE-2026-66490 Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 Gridbox · 1 source · MEDIUM CVSS 6.1 CVE-2026-66489 Various unauthenticated file system disclosure in Gridbox < 2.20.2 Gridbox · 1 source · MEDIUM CVSS 5.3 CVE-2026-66488 Payment bypass in Gridbox < 2.20.2 Gridbox · 1 source · MEDIUM CVSS 5.3 CVE-2026-65946 XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 ro_csvi · 1 source · MEDIUM CVSS 6.1