Total
398447 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-74803 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group. | |||||
| CVE-2026-76606 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2. | |||||
| CVE-2026-66915 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin. | |||||
| CVE-2026-77028 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | |||||
| CVE-2026-77992 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks. | |||||
| CVE-2026-77026 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | |||||
| CVE-2026-76608 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks. | |||||
| CVE-2026-67366 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check. | |||||
| CVE-2026-67361 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible. | |||||
| CVE-2026-77027 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector. | |||||
| CVE-2026-76565 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 | |||||
| CVE-2026-76613 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries. | |||||
| CVE-2026-74804 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping. | |||||
| CVE-2026-77993 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter. | |||||
| CVE-2026-76612 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector. | |||||
| CVE-2026-76598 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings. | |||||
| CVE-2026-74252 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name. | |||||
| CVE-2026-67363 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping. | |||||
| CVE-2026-67359 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to render the full checkout confirmation page for that order, including line items, prices, and totals. | |||||
| CVE-2026-76605 | 2026-08-26 | N/A | N/A | ||
| Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. | |||||
