База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 168

Критическая CVSS 9.1

CVE-2026-64798

Разработчикregularlabs.com

Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-64797

Разработчикregularlabs.com

IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic…

22.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-64796

Разработчикregularlabs.com

various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consisten…

22.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-64793

Разработчикregularlabs.com

Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished ar…

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-64792

Разработчикregularlabs.com

disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity inste…

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-64791

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-man…

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-63685

Разработчикregularlabs.com

Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend u…

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-63684

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests…

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-63683

Разработчикregularlabs.com

Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-63280

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

22.07.2026 Требует внимания
Высокая CVSS 8.0

CVE-2026-63265

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, m…

22.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-63048

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-63047

РасширениеEvents Booking
Разработчикjoomdonation.com

Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowe…

22.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62415

Разработчикjoomdonation.com

Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

21.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62414

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61900

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-61425

Разработчикbalbooa.com

Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61424

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания