Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-73373
Unrestricted uploads of SHTML files
HIGH
CVSS 8.9
CVE-2026-73337
MFA Authentication Bypass
HIGH
CVSS 8.2
CVE-2026-71574
Inconsistent ACL checks for mutating webservice endpoints
HIGH
CVSS 8.5
CVE-2025-25227
Joomla CMS Multi-Factor Authentication Bypass
HIGH
CVSS 7.5
CVE-2023-23755
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2022-23793
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2021-26036
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2021-26038
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2010-1434
Joomla! Core is prone to a session fixation vulnerability.
HIGH
CVSS 7.5
CVE-2010-1432
Joomla! Core is prone to an information disclosure vulnerability.
HIGH
CVSS 7.5
CVE-2021-23132
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2021-23131
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35616
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35612
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35611
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-35610
An issue was discovered in Joomla!
HIGH
CVSS 7.5
CVE-2020-13763
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
HIGH
CVSS 7.5
CVE-2020-13760
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
HIGH
CVSS 8.8
CVE-2020-10241
An issue was discovered in Joomla!
HIGH
CVSS 8.8
CVE-2020-10239
An issue was discovered in Joomla!
HIGH
CVSS 8.8