База уязвимостей Joomla

Все CVE Joomla.
В одной базе знаний.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновляется
1 419 уязвимостей в общем периоде
170за 3 месяца
85за месяц
57за неделю

Данные обновлены 24.07.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 169

Критическая CVSS 9.3

CVE-2026-65761

РасширениеEasy Store
Разработчикjoomshaper.com

Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read acce…

23.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65760

РасширениеEasy Store
Разработчикjoomshaper.com

cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any…

23.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-63048

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

22.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62415

Разработчикjoomdonation.com

Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

21.07.2026 Требует внимания
Критическая CVSS 9.1

CVE-2026-62414

Разработчикjoomlack.fr

Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61900

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-61425

Разработчикbalbooa.com

Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-61424

Разработчикdj

extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60034

Разработчикthemexpert.com

Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to st…

20.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-60032

Разработчикthemexpert.com

Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possib…

20.07.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-60024

Разработчикjoomdonation.com

Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

17.07.2026 Требует внимания
Критическая CVSS 9.0

CVE-2026-57828

РасширениеPhoca Download
Разработчикphoca.cz

Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading…

11.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-57827

РасширениеRsjoomla Rsfiles\!
Разработчикrsjoomla.com

Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files an…

11.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-56292

РасширениеAcymailing Acymailing
Разработчикacymailing.com

SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database ac…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56291

РасширениеBalbooa Forms
Разработчикbalbooa.com

Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executabl…

09.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56290

РасширениеJoomlack Page Builder Ck
Разработчикjoomlack.fr

Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading execu…

29.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48939

РасширениеJoomlic Icagenda
Разработчикicagenda

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

20.06.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48908

РасширениеSP Page Builder
РазработчикJoomShaper

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

20.06.2026 Требует внимания