Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2026-90905
Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 7.2
CVE-2026-90904
Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90903
Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 7.2
CVE-2026-90902
Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90901
Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.6
CVE-2026-90899
Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0
HIGH
CVSS 8.2
CVE-2026-88855
Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
HIGH
CVSS 8.6
CVE-2026-82189
Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 8.7
CVE-2026-81568
Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 8.7
CVE-2026-81567
Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 8.7
CVE-2026-78081
Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
HIGH
CVSS 7.1
CVE-2026-81564
Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0
HIGH
CVSS 7.0
CVE-2026-78375
Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1
HIGH
CVSS 8.6
CVE-2026-88853
Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0
HIGH
CVSS 7.5
CVE-2026-88852
Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0
HIGH
CVSS 7.5
CVE-2026-85195
Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0
HIGH
CVSS 7.5
CVE-2026-85191
Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0
HIGH
CVSS 7.5
CVE-2026-85190
Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5
HIGH
CVSS 7.5
CVE-2026-85189
Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0
HIGH
CVSS 7.5
CVE-2026-78302
Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4
HIGH
CVSS 8.6