Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

585 résultats

CVE-2026-76610 Unauthenticated tag modifications in Zoo < 4.1.65 Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-76569 Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 Extension Joomla — phoca.cz · 1 source · MEDIUM CVSS 5.3 CVE-2026-76565 Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 Extension Joomla — phoca.cz · 1 source · MEDIUM CVSS 5.3 CVE-2026-75955 Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-75952 Cross-site request forgery in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 4.6 CVE-2026-75951 Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-75950 Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 Extension Joomla — cmsjunkie.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-75114 Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 Extension Joomla — yootheme.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-73372 Improper ACL checks when injection schema.org contact data Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-73371 Improper ACL checks for batch copy actions Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-73336 XSS through schema.org outputs Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-72532 Improper ACL checks for category webservice endpoints Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-72531 Improper ACL checks for custom fields webservice endpoints Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-71573 Improper CORS origin validation Joomla CMS · 3 sources · MEDIUM CVSS 6.9 CVE-2026-71572 Response header injection in download views Joomla CMS · 3 sources · MEDIUM CVSS 4.8 CVE-2026-71570 ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 com_icagenda · 1 source · MEDIUM CVSS 5.1 CVE-2026-67366 CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 Extension Joomla — icagenda.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-67287 Unauthenticated comment creation in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67286 Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67284 Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 Extension Joomla — tabaoca.org · 1 source · MEDIUM CVSS 5.3