Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-76610
Unauthenticated tag modifications in Zoo < 4.1.65
MEDIUM
CVSS 6.9
CVE-2026-76569
Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
MEDIUM
CVSS 5.3
CVE-2026-76565
Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
MEDIUM
CVSS 5.3
CVE-2026-75955
Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 5.1
CVE-2026-75952
Cross-site request forgery in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 4.6
CVE-2026-75951
Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 6.9
CVE-2026-75950
Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3
MEDIUM
CVSS 6.9
CVE-2026-75114
Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64
MEDIUM
CVSS 5.1
CVE-2026-73372
Improper ACL checks when injection schema.org contact data
MEDIUM
CVSS 5.1
CVE-2026-73371
Improper ACL checks for batch copy actions
MEDIUM
CVSS 5.1
CVE-2026-73336
XSS through schema.org outputs
MEDIUM
CVSS 5.1
CVE-2026-72532
Improper ACL checks for category webservice endpoints
MEDIUM
CVSS 5.1
CVE-2026-72531
Improper ACL checks for custom fields webservice endpoints
MEDIUM
CVSS 5.1
CVE-2026-71573
Improper CORS origin validation
MEDIUM
CVSS 6.9
CVE-2026-71572
Response header injection in download views
MEDIUM
CVSS 4.8
CVE-2026-71570
ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11
MEDIUM
CVSS 5.1
CVE-2026-67366
CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11
MEDIUM
CVSS 5.3
CVE-2026-67287
Unauthenticated comment creation in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67286
Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67284
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3
MEDIUM
CVSS 5.3