Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-90900
Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0
MEDIUM
CVSS 5.3
CVE-2026-84048
Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2
MEDIUM
CVSS 6.3
CVE-2026-82191
Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
MEDIUM
CVSS 5.3
CVE-2026-82190
Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
MEDIUM
CVSS 6.3
CVE-2026-79701
Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6
MEDIUM
CVSS 6.9
CVE-2026-81566
Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0
MEDIUM
CVSS 5.1
CVE-2026-81565
Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0
MEDIUM
CVSS 6.9
CVE-2026-79700
Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4
MEDIUM
CVSS 6.9
CVE-2026-85196
Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0
MEDIUM
CVSS 5.3
CVE-2026-85188
Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla
MEDIUM
CVSS 6.9
CVE-2026-78085
Path Traversal in Gallery Image Management in SP Property < 4.1.4
MEDIUM
CVSS 6.9
CVE-2026-78374
Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0
MEDIUM
CVSS 6.9
CVE-2026-78303
Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4
MEDIUM
CVSS 6.9
CVE-2026-78084
Missing Access Control in Gallery Image Management in SP Property < 4.1.4
MEDIUM
CVSS 6.9
CVE-2026-78000
Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
MEDIUM
CVSS 5.3
CVE-2026-78079
Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10
MEDIUM
CVSS 5.3
CVE-2026-78076
Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10
MEDIUM
CVSS 5.1
CVE-2026-78075
Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10
MEDIUM
CVSS 5.1
CVE-2026-78073
Reflected XSS in All Video Share 1.0.0-4.5.0
MEDIUM
CVSS 5.3
CVE-2026-78070
Authenticated, privileged blind SQL injection in DP Calendar 5.5.0
MEDIUM
CVSS 6.9