Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-57828
Authenticated file upload in Phoca Downloads component < 6.1.3
CRITICAL
CVSS 9.0
CVE-2026-57827
Unauthenticated file upload in RSFiles component < 1.17.12
CRITICAL
CVSS 10.0
CVE-2026-56292
SQL Injection in AcyMailing extension < 10.11.1
CRITICAL
CVSS 9.2
CVE-2026-56291
Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CRITICAL
CVSS 10.0
CVE-2026-56290
Unauthenticated file upload in Page Builder CK extension < 3.6.0
CRITICAL
CVSS 10.0
CVE-2026-48939
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code uplo…
CRITICAL
CVSS 10.0
CVE-2026-48908
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP c…
CRITICAL
CVSS 10.0
CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code u…
CRITICAL
CVSS 10.0
CVE-2026-34424
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that all…
CRITICAL
CVSS 9.3
CVE-2026-21627
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point.
CRITICAL
CVSS 9.5
CVE-2026-21624
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
CRITICAL
CVSS 9.4
CVE-2026-21623
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
CRITICAL
CVSS 9.4
CVE-2025-40636
SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3.
CRITICAL
CVSS 9.3
CVE-2025-54473
An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered.
CRITICAL
CVSS 9.2
CVE-2025-54299
A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.
CRITICAL
CVSS 9.4
CVE-2025-54298
A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.
CRITICAL
CVSS 9.4
CVE-2025-54294
A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered.
CRITICAL
CVSS 9.3
CVE-2025-26855
A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.
CRITICAL
CVSS 9.8
CVE-2025-26854
A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.
CRITICAL
CVSS 9.8
CVE-2025-49467
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered.
CRITICAL
CVSS 9.3