База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 200

Критическая CVSS 9.3

CVE-2026-75954

Разработчикcmsjunkie.com

SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-75949

Разработчикcmsjunkie.com

Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees)…

19.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74804

Разработчикyootheme.com

Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.ty…

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74803

Разработчикyootheme.com

Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-67364

Разработчикbalbooa.com

Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handle…

19.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74254

Разработчикjoomlack.fr

SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the fro…

17.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74253

Разработчикregularlabs.com

Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML with…

17.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74251

РасширениеPhoca Cart
Разработчикphoca.cz

Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are co…

16.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-67365

Разработчикicagenda.com

Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

14.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-67285

Разработчикjoomshaper.com

Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.

12.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-67282

Разработчикfabrikar.com

Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

12.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-66915

Разработчикfabrikar.com

Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

10.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-66914

Разработчикseblod.com

Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.

07.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65888

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65887

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super…

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65886

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65890

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65889

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

29.07.2026 Требует внимания