База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Не оценена CVSS 0.0

CVE-2026-64872

Разработчикregularlabs.com

Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

23.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64871

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

23.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64799

Разработчикregularlabs.com

SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirect…

23.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64798

Разработчикregularlabs.com

Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64797

Разработчикregularlabs.com

IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64796

Разработчикregularlabs.com

various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consisten…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64795

Разработчикregularlabs.com

XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe mar…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64794

Разработчикregularlabs.com

restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64793

Разработчикregularlabs.com

Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished ar…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64792

Разработчикregularlabs.com

disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity inste…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-64791

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-man…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-63685

Разработчикregularlabs.com

Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend u…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-63684

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests…

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-63683

Разработчикregularlabs.com

Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-63281

Разработчикregularlabs.com

XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-63280

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

22.07.2026 Активна
Не оценена CVSS 0.0

CVE-2026-63265

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, m…

22.07.2026 Активна
Средняя CVSS 5.3

CVE-2026-63264

Разработчикjoomshopping.com

Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

22.07.2026 Активна