База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 200

Критическая CVSS 9.4

CVE-2026-65885

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65884

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissi…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65883

Разработчикaimy

extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65880

Разработчикbalbooa.com

Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

28.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-65879

Разработчикjoomshaper.com

Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

27.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65876

Разработчикjoomshaper.com

Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

27.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65766

Разработчикjoomshaper.com

Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

27.07.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-65761

РасширениеEasy Store
Разработчикjoomshaper.com

Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read acce…

23.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65760

РасширениеEasy Store
Разработчикjoomshaper.com

cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any…

23.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-65431

Разработчикregularlabs.com

Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

23.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-64874

Разработчикregularlabs.com

CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

23.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-64873

Разработчикregularlabs.com

SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

23.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-64798

Разработчикregularlabs.com

Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

22.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-64796

Разработчикregularlabs.com

various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consisten…

22.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-64793

Разработчикregularlabs.com

Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished ar…

22.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-63048

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

22.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62415

Разработчикjoomdonation.com

Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

21.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62414

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

20.07.2026 Требует внимания