База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Средняя CVSS 6.9

CVE-2026-77026

Разработчикtassos.gr

Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a for…

20.08.2026 Активна
Средняя CVSS 6.9

CVE-2026-76610

Разработчикyootheme.com

Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

20.08.2026 Активна
Средняя CVSS 5.3

CVE-2026-76569

РасширениеPhoca Download
Разработчикphoca.cz

Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

20.08.2026 Активна
Средняя CVSS 5.3

CVE-2026-76565

РасширениеPhoca Cart
Разработчикphoca.cz

Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

20.08.2026 Активна
Высокая CVSS 8.6

CVE-2026-75948

РасширениеiCagenda
Разработчикicagenda.com

Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.

20.08.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-75956

Разработчикcmsjunkie.com

DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP…

19.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-75955

Разработчикcmsjunkie.com

Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.

19.08.2026 Активна
Критическая CVSS 9.3

CVE-2026-75954

Разработчикcmsjunkie.com

SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.

19.08.2026 Требует внимания
Не оценена CVSS 0.0

CVE-2026-75953

Разработчикcmsjunkie.com

Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail co…

19.08.2026 Активна
Средняя CVSS 4.6

CVE-2026-75952

Разработчикcmsjunkie.com

Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generatio…

19.08.2026 Активна
Средняя CVSS 6.9

CVE-2026-75951

Разработчикcmsjunkie.com

Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

19.08.2026 Активна
Средняя CVSS 6.9

CVE-2026-75950

Разработчикcmsjunkie.com

Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had…

19.08.2026 Активна
Критическая CVSS 10.0

CVE-2026-75949

Разработчикcmsjunkie.com

Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees)…

19.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-75114

Разработчикyootheme.com

Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.

19.08.2026 Активна
Критическая CVSS 9.3

CVE-2026-74804

Разработчикyootheme.com

Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.ty…

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74803

Разработчикyootheme.com

Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-67364

Разработчикbalbooa.com

Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handle…

19.08.2026 Требует внимания