Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-73373
Unrestricted uploads of SHTML files
HIGH
CVSS 8.9
CVE-2026-73372
Improper ACL checks when injection schema.org contact data
MEDIUM
CVSS 5.1
CVE-2026-73371
Improper ACL checks for batch copy actions
MEDIUM
CVSS 5.1
CVE-2026-73337
MFA Authentication Bypass
HIGH
CVSS 8.2
CVE-2026-73336
XSS through schema.org outputs
MEDIUM
CVSS 5.1
CVE-2026-72532
Improper ACL checks for category webservice endpoints
MEDIUM
CVSS 5.1
CVE-2026-72531
Improper ACL checks for custom fields webservice endpoints
MEDIUM
CVSS 5.1
CVE-2026-71574
Inconsistent ACL checks for mutating webservice endpoints
HIGH
CVSS 8.5
CVE-2026-71573
Improper CORS origin validation
MEDIUM
CVSS 6.9
CVE-2026-71572
Response header injection in download views
MEDIUM
CVSS 4.8
CVE-2026-48947
Incorrect Access Control in com_media webservice endpoints
LOW
CVE-2026-48948
Incorrect Access Control in com_contact vcf download
LOW
CVE-2026-48949
XSS in MFA method management
MEDIUM
CVE-2026-48950
XSS in com_templates
MEDIUM
CVE-2026-48951
XSS in various modalreturn layouts
MEDIUM
CVE-2026-48952
XSS in com_installer
MEDIUM
CVE-2026-48953
XSS in the generic image output layout
MEDIUM
CVE-2026-48954
XSS through language overrides
MEDIUM
CVE-2026-48955
Incorrect Access Control in com_workflow
MEDIUM
CVE-2026-48956
Incorrect Access Control in com_modules
MEDIUM