База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Найдено: 1 419

Критическая CVSS 9.8

CVE-2026-60024

Разработчикjoomdonation.com

Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

17.07.2026 Требует внимания
Средняя CVSS 5.3

CVE-2026-58149

Разработчикjoomdonation.com

User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email add…

17.07.2026 Активна
Высокая CVSS 8.7

CVE-2026-58148

Разработчикchronoengine.com

Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

17.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58078

Разработчикthemexpert.com

Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

16.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58077

Разработчикweeblr.com

Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in…

15.07.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-57833

Разработчикweeblr.com

Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.

15.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57832

Разработчикjoomdonation.com

Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.

15.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57831

РасширениеDP Calendar
Разработчикdigital

peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.

15.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-57830

РасширениеHelix Ultimate
Разработчикjoomshaper.com

Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

13.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57829

РасширениеHelix Ultimate
Разработчикjoomshaper.com

Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

13.07.2026 Требует внимания
Критическая CVSS 9.0

CVE-2026-57828

РасширениеPhoca Download
Разработчикphoca.cz

Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading…

11.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-57827

РасширениеRsjoomla Rsfiles\!
Разработчикrsjoomla.com

Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files an…

11.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-56292

РасширениеAcymailing Acymailing
Разработчикacymailing.com

SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database ac…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56291

РасширениеBalbooa Forms
Разработчикbalbooa.com

Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executabl…

09.07.2026 Требует внимания
Средняя CVSS 6.4

CVE-2026-48955

Разработчикjoomla

An improper access check allows unauthorized users to access workflow stage and transition information.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48956

Разработчикjoomla

An improper access check allows users to display a list of modules in the frontend.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48957

Разработчикjoomla

An improper access check allows unauthorized users to access com_privacy datasets.

07.07.2026 Активна
Средняя CVSS 6.4

CVE-2026-48958

Разработчикjoomla

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

07.07.2026 Активна