Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-76610
Unauthenticated tag modifications in Zoo < 4.1.65
MEDIUM
CVSS 6.9
CVE-2026-76569
Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
MEDIUM
CVSS 5.3
CVE-2026-76565
Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
MEDIUM
CVSS 5.3
CVE-2026-75955
Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 5.1
CVE-2026-75952
Cross-site request forgery in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 4.6
CVE-2026-75951
Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 6.9
CVE-2026-75950
Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 6.9
CVE-2026-75114
Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64
MEDIUM
CVSS 5.1
CVE-2026-71570
ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11
MEDIUM
CVSS 5.1
CVE-2026-67366
CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11
MEDIUM
CVSS 5.3
CVE-2026-67287
Unauthenticated comment creation in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67286
Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67284
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3
MEDIUM
CVSS 5.3
CVE-2026-67283
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2
MEDIUM
CVSS 6.9
CVE-2026-66493
Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
MEDIUM
CVSS 6.4
CVE-2026-66492
Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
MEDIUM
CVSS 6.1
CVE-2026-66490
Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
MEDIUM
CVSS 6.1
CVE-2026-66489
Various unauthenticated file system disclosure in Gridbox < 2.20.2
MEDIUM
CVSS 5.3
CVE-2026-66488
Payment bypass in Gridbox < 2.20.2
MEDIUM
CVSS 5.3
CVE-2026-65946
XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
MEDIUM
CVSS 6.1