Каталог CVE

Разработчик: joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 103

Разработчик: joomla
Средняя CVSS 6.4

CVE-2026-48955

Разработчикjoomla

An improper access check allows unauthorized users to access workflow stage and transition information.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48956

Разработчикjoomla

An improper access check allows users to display a list of modules in the frontend.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48957

Разработчикjoomla

An improper access check allows unauthorized users to access com_privacy datasets.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48958

Разработчикjoomla

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

07.07.2026 Активна
Средняя CVSS 5.9

CVE-2026-48954

Разработчикjoomla

Improper validation leads to a generic XSS vector in the language override feature.

07.07.2026 Активна
Средняя CVSS 5.9

CVE-2026-48949

Разработчикjoomla

Lack of validation leads to an XSS vulnerability in the MFA management views.

07.07.2026 Активна
Средняя CVSS 5.9

CVE-2026-48950

Разработчикjoomla

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

07.07.2026 Активна
Средняя CVSS 5.9

CVE-2026-48951

Разработчикjoomla

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

07.07.2026 Активна
Средняя CVSS 5.9

CVE-2026-48952

Разработчикjoomla

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

07.07.2026 Активна
Средняя CVSS 5.9

CVE-2026-48953

Разработчикjoomla

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48947

Разработчикjoomla

An improper access check allows privileged users to overwrite media files without editing permissions.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48948

Разработчикjoomla

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

07.07.2026 Активна
Средняя CVSS 6.9

CVE-2026-48905

Разработчикjoomla

Lack of input filtering leads to an XSS vector in the HTML filter code.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-48903

Разработчикjoomla

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

26.05.2026 Активна
Высокая CVSS 8.2

CVE-2026-48904

Разработчикjoomla

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

26.05.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-48902

Разработчикjoomla

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48896

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48897

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания