База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 255

Критическая CVSS 9.2

CVE-2026-65890

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65889

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

29.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-65944

РасширениеRolandd Ro Csvi
Разработчикrolandd.com

CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

29.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-65943

РасширениеRolandd Ro Csvi
Разработчикrolandd.com

Unauthenticated directory creation RO CSVI < 9.11.0

29.07.2026 Требует внимания
Средняя CVSS 6.5

CVE-2026-65891

РасширениеJCE
Разработчикjoomlacontenteditor.net

Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an au…

29.07.2026 Активна
Критическая CVSS 9.4

CVE-2026-65885

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65884

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissi…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65883

Разработчикaimy

extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

29.07.2026 Требует внимания
Средняя CVSS 6.1

CVE-2026-65882

Разработчикjoomdle.com

Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.

28.07.2026 Активна
Высокая CVSS 7.5

CVE-2026-65881

Разработчикjoomdle.com

Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.

28.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65880

Разработчикbalbooa.com

Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

28.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-65879

Разработчикjoomshaper.com

Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

27.07.2026 Требует внимания
Высокая CVSS 8.3

CVE-2026-65878

Разработчикjoomshaper.com

Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

27.07.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-65877

Разработчикjoomshaper.com

Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

27.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65876

Разработчикjoomshaper.com

Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

27.07.2026 Требует внимания