База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 255

Средняя CVSS 5.3

CVE-2026-48899

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Активна
Высокая CVSS 8.2

CVE-2026-48898

Разработчикjoomla

An improper access check allows privilege escalation through the com_users batch task.

26.05.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-48902

Разработчикjoomla

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

26.05.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-48901

Разработчикjoomla

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48897

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-48896

Разработчикjoomla

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

26.05.2026 Требует внимания
Средняя CVSS 5.9

CVE-2026-40384

Разработчикjoomla

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

26.05.2026 Активна
Высокая CVSS 7.5

CVE-2026-40383

Разработчикjoomla

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

26.05.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-35223

Разработчикjoomla

An improper access check allows unauthorized access to com_config webservice endpoints.

26.05.2026 Требует внимания
Средняя CVSS 6.9

CVE-2026-35222

Разработчикjoomla

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-35221

Разработчикjoomla

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

26.05.2026 Активна
Средняя CVSS 4.6

CVE-2026-35220

Разработчикjoomla

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-30895

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-30894

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the content history component.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-25901

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the multilingual associations component.

26.05.2026 Активна
Средняя CVSS 6.9

CVE-2026-25900

Разработчикjoomla

Lack of output escaping leads to a XSS vector in the feed modules.

26.05.2026 Активна
Высокая CVSS 7.1

CVE-2018-25381

Разработчикextro.media

Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers…

25.05.2026 Требует внимания
Высокая CVSS 7.1

CVE-2018-25380

Разработчикextro.media

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, an…

25.05.2026 Требует внимания