База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 200

Критическая CVSS 10.0

CVE-2026-61900

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-61425

Разработчикbalbooa.com

Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61424

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60034

Разработчикthemexpert.com

Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to st…

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60032

Разработчикthemexpert.com

Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possib…

20.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-60024

Разработчикjoomdonation.com

Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

17.07.2026 Требует внимания
Критическая CVSS 9.0

CVE-2026-57828

РасширениеPhoca Download
Разработчикphoca.cz

Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users up…

11.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-57827

РасширениеRsjoomla Rsfiles\!
Разработчикrsjoomla.com

Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files an…

11.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-56292

РасширениеAcymailing Acymailing
Разработчикacymailing.com

SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database ac…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56291

РасширениеBalbooa Forms
Разработчикbalbooa.com

Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executabl…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56290

РасширениеJoomlack Page Builder Ck
Разработчикjoomlack.fr

Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading execu…

29.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48939

РасширениеJoomlic Icagenda
Разработчикicagenda

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

20.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48908

РасширениеSP Page Builder
РазработчикJoomShaper

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

20.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48907

РасширениеJCE
Разработчикjoomlacontenteditor

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

05.06.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-48902

Разработчикjoomla

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

26.05.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-34424

Разработчикpatchstack

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers…

09.04.2026 Требует внимания
Критическая CVSS 9.5

CVE-2026-21627

Разработчикtassos.gr

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functional…

20.02.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-21624

РасширениеStackideas Easydiscuss
Разработчикstackideas

Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.

16.01.2026 Требует внимания