Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1612 résultats

CVE-2026-73372 Improper ACL checks when injection schema.org contact data Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-73371 Improper ACL checks for batch copy actions Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-73337 MFA Authentication Bypass Joomla CMS · 3 sources · HIGH CVSS 8.2 CVE-2026-73336 XSS through schema.org outputs Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-72532 Improper ACL checks for category webservice endpoints Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-72531 Improper ACL checks for custom fields webservice endpoints Joomla CMS · 3 sources · MEDIUM CVSS 5.1 CVE-2026-71574 Inconsistent ACL checks for mutating webservice endpoints Joomla CMS · 3 sources · HIGH CVSS 8.5 CVE-2026-71573 Improper CORS origin validation Joomla CMS · 3 sources · MEDIUM CVSS 6.9 CVE-2026-71572 Response header injection in download views Joomla CMS · 3 sources · MEDIUM CVSS 4.8 CVE-2026-74251 Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 Extension Joomla — phoca.cz · 1 source · CRITICAL CVSS 9.3 CVE-2026-71570 ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 com_icagenda · 1 source · MEDIUM CVSS 5.1 CVE-2026-67366 CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 Extension Joomla — icagenda.com · 1 source · MEDIUM CVSS 5.3 CVE-2026-71571 Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 Extension Joomla — icagenda.com · 1 source · HIGH CVSS 8.6 CVE-2026-67365 Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 mod_icagenda_calendar · 1 source · CRITICAL CVSS 9.2 CVE-2026-67287 Unauthenticated comment creation in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67286 Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-67285 Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 Extension Joomla — joomshaper.com · 1 source · CRITICAL CVSS 9.2 CVE-2026-67284 Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 Extension Joomla — tabaoca.org · 1 source · MEDIUM CVSS 5.3 CVE-2026-67283 Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 Extension Joomla — tabaoca.org · 1 source · MEDIUM CVSS 6.9 CVE-2026-67282 Unauthenticated remote code execution in Fabrik < 4.6.8 Extension Joomla — fabrikar.com · 1 source · CRITICAL CVSS 10.0