CVE-2026-48901
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
An improper access check allows privilege escalation through the com_users batch task.
An improper access check allows privilege escalation through the com_users batch task.
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
An improper access check allows unauthorized access to com_config webservice endpoints.
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
Lack of output escaping leads to a XSS vector in the feed modules.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the content history component.
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.