CVE-2026-48898
An improper access check allows privilege escalation through the com_users batch task.
Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.
An improper access check allows privilege escalation through the com_users batch task.
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
An improper access check allows unauthorized access to com_config webservice endpoints.
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
Lack of output escaping leads to a XSS vector in the content history component.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the feed modules.
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.