Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

585 résultats

CVE-2026-64794 restricted user-data exposure in Users Anywhere and Articles Anywhere extensions Extension Joomla — regularlabs.com · 1 source · MEDIUM CVSS 6.5 CVE-2026-63281 XSS vulnerability in Regular Labs conditions manager Extension Joomla — regularlabs.com · 1 source · MEDIUM CVSS 4.8 CVE-2026-63264 Reflective XSS in JoomShopping < 5.9.3 Extension Joomla — joomshopping.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-61901 Open redirect in Hikashop < 6.5.2 Extension Joomla — hikashop.com · 1 source · MEDIUM CVSS 6.1 CVE-2026-60033 SSRF via remote download in JMedia Extension < 1.6.0 Extension Joomla — themexpert.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-60031 Information disclosure in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-60029 Authenticated stored XSS in Quix Page Builder < 6.2.1 Extension Joomla — themexpert.com · 1 source · MEDIUM CVSS 5.1 CVE-2026-58149 User enumeration in Events Booking < 5.8.0 Extension Joomla — joomdonation.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-48949 XSS in MFA method management Joomla CMS · 2 sources · MEDIUM CVE-2026-48950 XSS in com_templates Joomla CMS · 2 sources · MEDIUM CVE-2026-48951 XSS in various modalreturn layouts Joomla CMS · 2 sources · MEDIUM CVE-2026-48952 XSS in com_installer Joomla CMS · 2 sources · MEDIUM CVE-2026-48953 XSS in the generic image output layout Joomla CMS · 2 sources · MEDIUM CVE-2026-48954 XSS through language overrides Joomla CMS · 2 sources · MEDIUM CVE-2026-48955 Incorrect Access Control in com_workflow Joomla CMS · 2 sources · MEDIUM CVE-2026-48956 Incorrect Access Control in com_modules Joomla CMS · 2 sources · MEDIUM CVE-2026-48957 Incorrect Access Control in com_privacy webservice endpoints Joomla CMS · 2 sources · MEDIUM CVE-2026-48958 Incorrect Access Control in com_fields webservice endpoints Joomla CMS · 2 sources · MEDIUM CVE-2026-48943 K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. k2 · 1 source · MEDIUM CVSS 6.5 CVE-2019-25760 Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base… easy_shop · 1 source · MEDIUM CVSS 6.9