Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

642 résultats

CVE-2026-65430 MaxMind Credential leakage in GeoIP extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64876 Inconsistent CSRF token checks / privilege checks in GeoIP extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-64799 SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64797 IP spoofing vulnerability in IP login extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64792 disclosure of restricted content via search index in various Regular Labs extensions Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64791 Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63685 Authorization bypass in DB Replacer extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63684 Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63683 Client IP spoofing vulnerability in Regular Labs conditions manager Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-63280 Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63265 Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.0 CVE-2026-63047 Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 Extension Joomla — joomdonation.com · 1 source · HIGH CVSS 7.5 CVE-2026-60030 Broken Access Control for media management in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.7 CVE-2026-60028 Authenticated stored XSS in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.6 CVE-2026-60027 Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.7 CVE-2026-60026 Authenticated PHP code execution in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.9 CVE-2026-60025 User enumeration in Events Booking < 5.8.0 Extension Joomla — joomdonation.com · 1 source · HIGH CVSS 8.8 CVE-2026-58148 Stored XSS in ChronoForms extension for Joomla 8.0 ChronoForms · 1 source · HIGH CVSS 8.7 CVE-2026-58078 Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.7 CVE-2026-58077 Unauthenticated stored XSS in 4Analytics < 5.0.2 Extension Joomla — weeblr.com · 1 source · HIGH CVSS 8.7