Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-65757
Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension
HIGH
CVSS 8.1
CVE-2026-65755
Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension
HIGH
CVSS 7.5
CVE-2026-65754
Insecure path handling in ReReplacer Pro extension
HIGH
CVSS 7.5
CVE-2026-65430
MaxMind Credential leakage in GeoIP extension
HIGH
CVSS 7.5
CVE-2026-64876
Inconsistent CSRF token checks / privilege checks in GeoIP extension
HIGH
CVSS 8.8
CVE-2026-64799
SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions
HIGH
CVSS 7.5
CVE-2026-64797
IP spoofing vulnerability in IP login extension
HIGH
CVSS 7.5
CVE-2026-64792
disclosure of restricted content via search index in various Regular Labs extensions
HIGH
CVSS 7.5
CVE-2026-64791
Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager
HIGH
CVSS 8.8
CVE-2026-63685
Authorization bypass in DB Replacer extension
HIGH
CVSS 8.8
CVE-2026-63684
Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension
HIGH
CVSS 8.8
CVE-2026-63683
Client IP spoofing vulnerability in Regular Labs conditions manager
HIGH
CVSS 7.5
CVE-2026-63280
Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager
HIGH
CVSS 8.8
CVE-2026-63265
Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints
HIGH
CVSS 8.0
CVE-2026-63047
Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1
HIGH
CVSS 7.5
CVE-2026-60030
Broken Access Control for media management in Quix Page Builder < 6.2.1
HIGH
CVSS 8.7
CVE-2026-60028
Authenticated stored XSS in Quix Page Builder < 6.2.1
HIGH
CVSS 8.6
CVE-2026-60027
Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1
HIGH
CVSS 8.7
CVE-2026-60026
Authenticated PHP code execution in Quix Page Builder < 6.2.1
HIGH
CVSS 8.9
CVE-2026-60025
User enumeration in Events Booking < 5.8.0
HIGH
CVSS 8.8