База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 494

Не оценена CVSS 0.0

CVE-2026-73327

РазработчикНе указан в CVE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and…

12.08.2026 Активна
Средняя CVSS 6.3

CVE-2026-67287

Разработчикjoomshaper.com

Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in questi…

12.08.2026 Активна
Средняя CVSS 6.3

CVE-2026-67286

Разработчикjoomshaper.com

Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

12.08.2026 Активна
Критическая CVSS 9.2

CVE-2026-67285

Разработчикjoomshaper.com

Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.

12.08.2026 Требует внимания
Средняя CVSS 5.3

CVE-2026-67284

Разработчикtabaoca.org

Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permission…

12.08.2026 Активна
Средняя CVSS 6.9

CVE-2026-67283

Разработчикtabaoca.org

Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissi…

12.08.2026 Активна
Критическая CVSS 10.0

CVE-2026-67282

Разработчикfabrikar.com

Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

12.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-66915

Разработчикfabrikar.com

Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

10.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-66914

Разработчикseblod.com

Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.

07.08.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-66494

Разработчикjoomshaper.com

Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request.…

07.08.2026 Требует внимания
Средняя CVSS 6.4

CVE-2026-66493

РасширениеPhoca Commander
Разработчикphoca.cz

Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.

07.08.2026 Активна
Средняя CVSS 6.1

CVE-2026-66492

РасширениеPhoca Commander
Разработчикphoca.cz

Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.

07.08.2026 Активна
Высокая CVSS 8.2

CVE-2026-66491

РасширениеPhoca Commander
Разработчикphoca.cz

Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

07.08.2026 Требует внимания
Высокая CVSS 7.3

CVE-2026-65947

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Various CSRF vectors in the admin interface in Gridbox < 2.20.2

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65888

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65887

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super…

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65886

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

29.07.2026 Требует внимания
Средняя CVSS 6.1

CVE-2026-66490

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

29.07.2026 Активна