Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-71570
ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11
MEDIUM
CVSS 5.1
CVE-2026-67366
CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11
MEDIUM
CVSS 5.3
CVE-2026-71571
Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11
HIGH
CVSS 8.6
CVE-2026-67365
Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11
CRITICAL
CVSS 9.2
CVE-2026-67287
Unauthenticated comment creation in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67286
Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0
MEDIUM
CVSS 6.3
CVE-2026-67285
Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0
CRITICAL
CVSS 9.2
CVE-2026-67284
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3
MEDIUM
CVSS 5.3
CVE-2026-67283
Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2
MEDIUM
CVSS 6.9
CVE-2026-67282
Unauthenticated remote code execution in Fabrik < 4.6.8
CRITICAL
CVSS 10.0
CVE-2026-66915
Remote code execution in Fabrik < 4.7.2
CRITICAL
CVSS 10.0
CVE-2026-66914
Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1
CRITICAL
CVSS 9.2
CVE-2026-66494
Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0
HIGH
CVSS 8.7
CVE-2026-66493
Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
MEDIUM
CVSS 6.4
CVE-2026-66492
Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
MEDIUM
CVSS 6.1
CVE-2026-66491
Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
HIGH
CVSS 8.2
CVE-2026-65947
Various CSRF vectors in the admin interface in Gridbox < 2.20.2
HIGH
CVSS 7.3
CVE-2026-65888
Account takeover vulnerability in Gridbox < 2.20.2
CRITICAL
CVSS 10.0
CVE-2026-65887
Unauthenticated arbitrary password reset in Gridbox < 2.20.2
CRITICAL
CVSS 10.0
CVE-2026-65886
Unauthenticated arbitrary file read in Gridbox < 2.20.2
CRITICAL
CVSS 9.2