Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-64794
restricted user-data exposure in Users Anywhere and Articles Anywhere extensions
MEDIUM
CVSS 6.5
CVE-2026-63281
XSS vulnerability in Regular Labs conditions manager
MEDIUM
CVSS 4.8
CVE-2026-63264
Reflective XSS in JoomShopping < 5.9.3
MEDIUM
CVSS 5.3
CVE-2026-61901
Open redirect in Hikashop < 6.5.2
MEDIUM
CVSS 6.1
CVE-2026-60033
SSRF via remote download in JMedia Extension < 1.6.0
MEDIUM
CVSS 5.1
CVE-2026-60031
Information disclosure in Quix Page Builder < 6.2.1
MEDIUM
CVSS 6.9
CVE-2026-60029
Authenticated stored XSS in Quix Page Builder < 6.2.1
MEDIUM
CVSS 5.1
CVE-2026-58149
User enumeration in Events Booking < 5.8.0
MEDIUM
CVSS 5.3
CVE-2026-48949
XSS in MFA method management
MEDIUM
CVE-2026-48950
XSS in com_templates
MEDIUM
CVE-2026-48951
XSS in various modalreturn layouts
MEDIUM
CVE-2026-48952
XSS in com_installer
MEDIUM
CVE-2026-48953
XSS in the generic image output layout
MEDIUM
CVE-2026-48954
XSS through language overrides
MEDIUM
CVE-2026-48955
Incorrect Access Control in com_workflow
MEDIUM
CVE-2026-48956
Incorrect Access Control in com_modules
MEDIUM
CVE-2026-48957
Incorrect Access Control in com_privacy webservice endpoints
MEDIUM
CVE-2026-48958
Incorrect Access Control in com_fields webservice endpoints
MEDIUM
CVE-2026-48943
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`.
MEDIUM
CVSS 6.5
CVE-2019-25760
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base…
MEDIUM
CVSS 6.9