База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 107

Критическая CVSS 9.8

CVE-2026-60024

Разработчикjoomdonation.com

Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

17.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58148

Разработчикchronoengine.com

Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

17.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58078

Разработчикthemexpert.com

Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

16.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58077

Разработчикweeblr.com

Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in…

15.07.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-57833

Разработчикweeblr.com

Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.

15.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57832

Разработчикjoomdonation.com

Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.

15.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57831

РасширениеDP Calendar
Разработчикdigital

peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.

15.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-57830

РасширениеHelix Ultimate
Разработчикjoomshaper.com

Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

13.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57829

РасширениеHelix Ultimate
Разработчикjoomshaper.com

Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

13.07.2026 Требует внимания
Критическая CVSS 9.0

CVE-2026-57828

РасширениеPhoca Download
Разработчикphoca.cz

Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading…

11.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-57827

РасширениеRsjoomla Rsfiles\!
Разработчикrsjoomla.com

Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files an…

11.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-56292

РасширениеAcymailing Acymailing
Разработчикacymailing.com

SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database ac…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56291

РасширениеBalbooa Forms
Разработчикbalbooa.com

Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executabl…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56290

РасширениеJoomlack Page Builder Ck
Разработчикjoomlack.fr

Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading execu…

29.06.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-49049

РасширениеHelix3
РазработчикJoomShaper

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

29.06.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-49048

РасширениеJoomcoder Joomcck
Разработчикjoomcoder

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without es…

28.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48939

РасширениеJoomlic Icagenda
Разработчикicagenda

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

20.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48908

РасширениеSP Page Builder
РазработчикJoomShaper

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

20.06.2026 Требует внимания