База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 168

Критическая CVSS 9.4

CVE-2026-60034

Разработчикthemexpert.com

Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to st…

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60032

Разработчикthemexpert.com

Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possib…

20.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-60030

Разработчикthemexpert.com

Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could u…

20.07.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-60028

Разработчикthemexpert.com

Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user cou…

20.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-60027

Разработчикthemexpert.com

Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Una…

20.07.2026 Требует внимания
Высокая CVSS 8.9

CVE-2026-60026

Разработчикthemexpert.com

Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (…

20.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-60025

Разработчикjoomdonation.com

User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

17.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-60024

Разработчикjoomdonation.com

Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

17.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58148

Разработчикchronoengine.com

Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

17.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58078

Разработчикthemexpert.com

Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

16.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58077

Разработчикweeblr.com

Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in…

15.07.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-57833

Разработчикweeblr.com

Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.

15.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57832

Разработчикjoomdonation.com

Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.

15.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57831

РасширениеDP Calendar
Разработчикdigital

peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.

15.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-57830

РасширениеHelix Ultimate
Разработчикjoomshaper.com

Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

13.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-57829

РасширениеHelix Ultimate
Разработчикjoomshaper.com

Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

13.07.2026 Требует внимания
Критическая CVSS 9.0

CVE-2026-57828

РасширениеPhoca Download
Разработчикphoca.cz

Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users up…

11.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-57827

РасширениеRsjoomla Rsfiles\!
Разработчикrsjoomla.com

Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files an…

11.07.2026 Требует внимания