Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

750 résultats

CVE-2026-90905 Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 7.2 CVE-2026-90904 Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.6 CVE-2026-90903 Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.2 CVE-2026-90902 Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 8.6 CVE-2026-90901 Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 com_easystore · 1 source · HIGH CVSS 8.6 CVE-2026-90899 Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.2 CVE-2026-88855 Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 OrdaSoft Joomla Gallery free · 1 source · HIGH CVSS 8.6 CVE-2026-82189 Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-81568 Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-81567 Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 8.7 CVE-2026-78081 Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 Extension Joomla — j2commerce.com · 1 source · HIGH CVSS 7.1 CVE-2026-81564 Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 7.0 CVE-2026-78375 Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 com_content · 1 source · HIGH CVSS 8.6 CVE-2026-88853 Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 Modals · 1 source · HIGH CVSS 7.5 CVE-2026-88852 Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 Snippets (Free) · 1 source · HIGH CVSS 7.5 CVE-2026-85195 Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 Articles Anywhere (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85191 Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 Tabs & Accordions (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85190 Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 Quick Index (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-85189 Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 Modals (Free, Pro) · 1 source · HIGH CVSS 7.5 CVE-2026-78302 Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 Extension Joomla — joomshaper.com · 1 source · HIGH CVSS 8.6