Vulnerabilities (CVE)

Filtered by vendor Joomla Subscribe
Filtered by product Joomla\!
Total 653 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-71574 1 Joomla 1 Joomla\! 2026-09-03 N/A 6.5 MEDIUM
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
CVE-2026-72532 1 Joomla 1 Joomla\! 2026-09-03 N/A 5.4 MEDIUM
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
CVE-2026-73373 1 Joomla 1 Joomla\! 2026-09-03 N/A 9.8 CRITICAL
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
CVE-2026-71572 1 Joomla 1 Joomla\! 2026-09-03 N/A 5.4 MEDIUM
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
CVE-2026-71573 1 Joomla 1 Joomla\! 2026-09-03 N/A 8.3 HIGH
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
CVE-2026-72531 1 Joomla 1 Joomla\! 2026-09-03 N/A 5.4 MEDIUM
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
CVE-2026-73336 1 Joomla 1 Joomla\! 2026-09-03 N/A 6.4 MEDIUM
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
CVE-2026-73372 1 Joomla 1 Joomla\! 2026-09-03 N/A 4.3 MEDIUM
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
CVE-2026-73371 1 Joomla 1 Joomla\! 2026-09-03 N/A 4.3 MEDIUM
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
CVE-2026-73337 1 Joomla 1 Joomla\! 2026-09-03 N/A 7.5 HIGH
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-35223 1 Joomla 1 Joomla\! 2026-07-24 N/A 9.8 CRITICAL
An improper access check allows unauthorized access to com_config webservice endpoints.
CVE-2026-48897 1 Joomla 1 Joomla\! 2026-07-24 N/A 7.5 HIGH
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48902 1 Joomla 1 Joomla\! 2026-07-24 N/A 9.8 CRITICAL
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVE-2026-25901 1 Joomla 1 Joomla\! 2026-07-24 N/A 6.1 MEDIUM
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-48901 1 Joomla 1 Joomla\! 2026-07-24 N/A 7.5 HIGH
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48898 1 Joomla 1 Joomla\! 2026-07-24 N/A 9.8 CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48896 1 Joomla 1 Joomla\! 2026-07-24 N/A 7.5 HIGH
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-30894 1 Joomla 1 Joomla\! 2026-07-24 N/A 6.1 MEDIUM
Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-40383 1 Joomla 1 Joomla\! 2026-07-24 N/A 9.8 CRITICAL
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-35221 1 Joomla 1 Joomla\! 2026-07-24 N/A 9.8 CRITICAL
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.