Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-73372
Improper ACL checks when injection schema.org contact data
MEDIUM
CVSS 5.1
CVE-2026-73371
Improper ACL checks for batch copy actions
MEDIUM
CVSS 5.1
CVE-2026-73337
MFA Authentication Bypass
HIGH
CVSS 8.2
CVE-2026-73336
XSS through schema.org outputs
MEDIUM
CVSS 5.1
CVE-2026-72532
Improper ACL checks for category webservice endpoints
MEDIUM
CVSS 5.1
CVE-2026-72531
Improper ACL checks for custom fields webservice endpoints
MEDIUM
CVSS 5.1
CVE-2026-71574
Inconsistent ACL checks for mutating webservice endpoints
HIGH
CVSS 8.5
CVE-2026-71573
Improper CORS origin validation
MEDIUM
CVSS 6.9
CVE-2026-71572
Response header injection in download views
MEDIUM
CVSS 4.8
CVE-2026-74251
Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
CRITICAL
CVSS 9.3
CVE-2026-71570
ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11
MEDIUM
CVSS 5.1
CVE-2026-67366
CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11
MEDIUM
CVSS 5.3
CVE-2026-71571
Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11
HIGH
CVSS 8.6
CVE-2026-67365
Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11
CRITICAL
CVSS 9.2
CVE-2026-67287
Unauthenticated comment creation in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67286
Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67285
Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0
CRITICAL
CVSS 9.2
CVE-2026-67284
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3
MEDIUM
CVSS 5.3
CVE-2026-67283
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2
MEDIUM
CVSS 6.9
CVE-2026-67282
Unauthenticated remote code execution in Fabrik < 4.6.8
CRITICAL
CVSS 10.0