База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 107

Критическая CVSS 9.3

CVE-2026-65761

РасширениеEasy Store
Разработчикjoomshaper.com

Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read acce…

23.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65760

РасширениеEasy Store
Разработчикjoomshaper.com

cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any…

23.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-65759

РасширениеEasy Store
Разработчикjoomshaper.com

unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthen…

23.07.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-65758

РасширениеConvert Forms
Разработчикtassos.gr

Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's subm…

23.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-63048

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-63047

РасширениеEvents Booking
Разработчикjoomdonation.com

Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowe…

22.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62415

Разработчикjoomdonation.com

Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

21.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62414

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61900

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-61425

Разработчикbalbooa.com

Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61424

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60034

Разработчикthemexpert.com

Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to st…

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60032

Разработчикthemexpert.com

Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possib…

20.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-60030

Разработчикthemexpert.com

Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could u…

20.07.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-60028

Разработчикthemexpert.com

Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user cou…

20.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-60027

Разработчикthemexpert.com

Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Una…

20.07.2026 Требует внимания
Высокая CVSS 8.9

CVE-2026-60026

Разработчикthemexpert.com

Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (…

20.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-60025

Разработчикjoomdonation.com

User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

17.07.2026 Требует внимания