Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-76598
Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2
HIGH
CVSS 8.7
CVE-2026-76597
Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2
HIGH
CVSS 8.7
CVE-2026-76596
Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
HIGH
CVSS 8.7
CVE-2026-76571
Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2
CRITICAL
CVSS 9.3
CVE-2026-66917
Stored XSS in JoomGallery < 4.4.0
HIGH
CVSS 8.6
CVE-2026-66916
Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctly enforces the password gate
MEDIUM
CVSS 6.9
CVE-2026-74252
Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
HIGH
CVSS 8.6
CVE-2026-67362
Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 5.1
CVE-2026-67361
Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 6.9
CVE-2026-67360
Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 6.3
CVE-2026-67359
Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
HIGH
CVSS 8.7
CVE-2026-67358
Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
MEDIUM
CVSS 5.3
CVE-2026-77028
Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
MEDIUM
CVSS 5.3
CVE-2026-76613
Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40
HIGH
CVSS 8.6
CVE-2026-76612
Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66
HIGH
CVSS 8.6
CVE-2026-76611
Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
MEDIUM
CVSS 6.9
CVE-2026-75115
Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40
HIGH
CVSS 7.0
CVE-2026-77029
Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
MEDIUM
CVSS 4.6
CVE-2026-77026
Client-controlled validation bypass in Convert Forms extension < 5.2.5
MEDIUM
CVSS 6.9
CVE-2026-76610
Unauthenticated tag modifications in Zoo < 4.1.65
MEDIUM
CVSS 6.9