Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

750 résultats

CVE-2026-65757 Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.1 CVE-2026-65755 Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-65754 Insecure path handling in ReReplacer Pro extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-65430 MaxMind Credential leakage in GeoIP extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64876 Inconsistent CSRF token checks / privilege checks in GeoIP extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-64799 SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64797 IP spoofing vulnerability in IP login extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64792 disclosure of restricted content via search index in various Regular Labs extensions Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-64791 Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63685 Authorization bypass in DB Replacer extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63684 Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63683 Client IP spoofing vulnerability in Regular Labs conditions manager Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 7.5 CVE-2026-63280 Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.8 CVE-2026-63265 Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints Extension Joomla — regularlabs.com · 1 source · HIGH CVSS 8.0 CVE-2026-63047 Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 Extension Joomla — joomdonation.com · 1 source · HIGH CVSS 7.5 CVE-2026-60030 Broken Access Control for media management in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.7 CVE-2026-60028 Authenticated stored XSS in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.6 CVE-2026-60027 Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.7 CVE-2026-60026 Authenticated PHP code execution in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · HIGH CVSS 8.9 CVE-2026-60025 User enumeration in Events Booking < 5.8.0 Extension Joomla — joomdonation.com · 1 source · HIGH CVSS 8.8