Total
7701 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-58429 | 2026-08-26 | N/A | 4.9 MEDIUM | ||
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | |||||
| CVE-2026-58508 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |||||
| CVE-2026-55979 | 2026-08-26 | N/A | 5.2 MEDIUM | ||
| An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies. | |||||
| CVE-2026-55978 | 2026-08-26 | N/A | 8.4 HIGH | ||
| An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement. | |||||
| CVE-2026-67283 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension. | |||||
| CVE-2026-75950 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings. | |||||
| CVE-2026-66494 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically.. | |||||
| CVE-2026-77997 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions. | |||||
| CVE-2026-67284 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users. | |||||
| CVE-2026-76599 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns. | |||||
| CVE-2026-76603 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users. | |||||
| CVE-2026-66916 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctly enforces the password gate - but the JSON view ( format=json ) skips this check entirely. | |||||
| CVE-2026-67287 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | |||||
| CVE-2026-76607 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. | |||||
| CVE-2026-76609 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks. | |||||
| CVE-2026-76610 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users. | |||||
| CVE-2026-76597 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot. | |||||
| CVE-2026-76596 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table | |||||
| CVE-2026-71570 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles. | |||||
| CVE-2026-76601 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks. | |||||
