Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-65879
Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1
CRITICAL
CVSS 9.8
CVE-2026-65876
Unauthenticated SQL injection in SP Page Builder < 6.8.0
CRITICAL
CVSS 9.2
CVE-2026-65766
Unauthenticated SQL injection in SP Page Builder < 6.7.1
CRITICAL
CVSS 9.2
CVE-2026-65761
Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
CRITICAL
CVSS 9.3
CVE-2026-65760
cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1
CRITICAL
CVSS 9.2
CVE-2026-65431
Zipslip in GeoIP extension
CRITICAL
CVSS 9.8
CVE-2026-64874
CDN Credential leakage Cache Cleaner Pro extension
CRITICAL
CVSS 9.8
CVE-2026-64873
SSRF in Cache Cleaner Pro extension
CRITICAL
CVSS 9.8
CVE-2026-64798
Insecure login URL keys in IP login extension
CRITICAL
CVSS 9.1
CVE-2026-64796
various code injection vectors in Sourcerer extension
CRITICAL
CVSS 9.8
CVE-2026-64793
Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions
CRITICAL
CVSS 9.1
CVE-2026-63048
Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2
CRITICAL
CVSS 9.4
CVE-2026-62415
Insecure default configuration Membership Pro < 4.6.2
CRITICAL
CVSS 9.1
CVE-2026-62414
Improper access control in Page Builder CK < 3.6.2
CRITICAL
CVSS 9.1
CVE-2026-61900
Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CRITICAL
CVSS 10.0
CVE-2026-61425
Authentication bypass in Gridbox < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-61424
Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
CRITICAL
CVSS 10.0
CVE-2026-60034
Authenticated stored XSS in JMedia Extension < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-60032
Authenticated arbitrary file upload in JMedia < 1.6.0
CRITICAL
CVSS 9.4
CVE-2026-60024
Insecure default configuration Events Booking < 5.8.0
CRITICAL
CVSS 9.8