Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-65886
Unauthenticated arbitrary file read in Gridbox < 2.20.2
CRITICAL
CVSS 9.2
CVE-2026-66490
Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
MEDIUM
CVSS 6.1
CVE-2026-66489
Various unauthenticated file system disclosure in Gridbox < 2.20.2
MEDIUM
CVSS 5.3
CVE-2026-66488
Payment bypass in Gridbox < 2.20.2
MEDIUM
CVSS 5.3
CVE-2026-65890
Unauthenticated SQL injection in Gridbox < 2.20.2
CRITICAL
CVSS 9.2
CVE-2026-65889
Unauthenticated recursive directory deletion < 2.20.2
CRITICAL
CVSS 9.2
CVE-2026-65946
XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
MEDIUM
CVSS 6.1
CVE-2026-65944
CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
HIGH
CVSS 8.8
CVE-2026-65943
Unauthenticated directory creation RO CSVI < 9.11.0
HIGH
CVSS 7.5
CVE-2026-65891
Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2
MEDIUM
CVSS 6.5
CVE-2026-65885
Authenticated arbitrary file upload in Gridbox < 2.20.2
CRITICAL
CVSS 9.4
CVE-2026-65884
Privilege Escalation in Gridbox < 2.20.2
CRITICAL
CVSS 10.0
CVE-2026-65883
RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0
CRITICAL
CVSS 10.0
CVE-2026-65882
Reflected XSS vulnerability in Joomdle < 3.1.1
MEDIUM
CVSS 6.1
CVE-2026-65881
Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
HIGH
CVSS 7.5
CVE-2026-65880
Unauthenticated remote code execution in Balbooa Forms < 2.4.3
CRITICAL
CVSS 10.0
CVE-2026-65879
Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1
CRITICAL
CVSS 9.8
CVE-2026-65878
Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.
HIGH
CVSS 8.3
CVE-2026-65877
Authenticated SQL injection in SP Page Builder < 6.7.1
HIGH
CVSS 8.2
CVE-2026-65876
Unauthenticated SQL injection in SP Page Builder < 6.8.0
CRITICAL
CVSS 9.2