База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 168

Критическая CVSS 10.0

CVE-2026-67282

Разработчикfabrikar.com

Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

12.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-66915

Разработчикfabrikar.com

Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

10.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-66914

Разработчикseblod.com

Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.

07.08.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-66494

Разработчикjoomshaper.com

Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request.…

07.08.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-66491

РасширениеPhoca Commander
Разработчикphoca.cz

Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

07.08.2026 Требует внимания
Высокая CVSS 7.3

CVE-2026-65947

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Various CSRF vectors in the admin interface in Gridbox < 2.20.2

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65888

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65887

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super…

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65886

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65890

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65889

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

29.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-65944

РасширениеRolandd Ro Csvi
Разработчикrolandd.com

CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

29.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-65943

РасширениеRolandd Ro Csvi
Разработчикrolandd.com

Unauthenticated directory creation RO CSVI < 9.11.0

29.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-65885

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65884

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissi…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65883

Разработчикaimy

extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

29.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-65881

Разработчикjoomdle.com

Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.

28.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65880

Разработчикbalbooa.com

Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

28.07.2026 Требует внимания