База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Высокая CVSS 7.7

CVE-2026-67363

Разработчикbalbooa.com

Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it…

19.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-73372

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unacc…

18.08.2026 Активна
Средняя CVSS 5.1

CVE-2026-73336

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

18.08.2026 Активна
Средняя CVSS 5.1

CVE-2026-72531

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fiel…

18.08.2026 Активна
Средняя CVSS 6.9

CVE-2026-71573

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated i…

18.08.2026 Активна
Средняя CVSS 4.8

CVE-2026-71572

Расширениеdownload views in Joomla
Разработчикdeveloper.joomla

Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download vi…

18.08.2026 Активна
Высокая CVSS 8.9

CVE-2026-73373

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that execute…

18.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-73371

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operatio…

18.08.2026 Активна
Высокая CVSS 8.2

CVE-2026-73337

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

18.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-72532

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categorie…

18.08.2026 Активна
Высокая CVSS 8.5

CVE-2026-71574

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform muta…

18.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74254

Разработчикjoomlack.fr

SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the fro…

17.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74253

Разработчикregularlabs.com

Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML with…

17.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74251

РасширениеPhoca Cart
Разработчикphoca.cz

Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are co…

16.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-71570

Разработчикicagenda.com

ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.

14.08.2026 Активна
Средняя CVSS 5.3

CVE-2026-67366

Разработчикicagenda.com

CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

14.08.2026 Активна
Высокая CVSS 8.6

CVE-2026-71571

Разработчикicagenda.com

Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

14.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-67365

Разработчикicagenda.com

Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

14.08.2026 Требует внимания