Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1213 résultats

CVE-2026-90905 Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 7.2 CVE-2026-90904 Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.6 CVE-2026-90903 Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.2 CVE-2026-90902 Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 8.6 CVE-2026-90901 Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 8.6 CVE-2026-90900 Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · MEDIUM CVSS 5.3 CVE-2026-90899 Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.2 CVE-2026-88857 Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · CRITICAL CVSS 9.4 CVE-2026-88856 Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · CRITICAL CVSS 9.4 CVE-2026-88855 Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · HIGH CVSS 8.6 CVE-2026-88854 Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · CRITICAL CVSS 9.3 CVE-2026-84048 Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 Extension Joomla — joomgalleryfriends.net · 1 source · MEDIUM CVSS 6.3 CVE-2026-82191 Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 com_j2store · 1 source · MEDIUM CVSS 5.3 CVE-2026-82190 Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · MEDIUM CVSS 6.3 CVE-2026-82189 Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-81568 Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-81567 Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-78081 Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 7.1 CVE-2026-79701 Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 Extension Joomla — joomshaper.com · 1 source · MEDIUM CVSS 6.9 CVE-2026-81566 Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 com_menus · 1 source · MEDIUM CVSS 5.1