База уязвимостей Joomla

CVE Joomla.
Устраните уязвимости до заражения сайта.

Проверяйте риски раньше, чем они станут инцидентом. Поиск по ядру Joomla и популярным расширениям, оценка CVSS и прямые ссылки на первичные источники.

Динамика уязвимостей Обновлено
1 494 уязвимостей в общем периоде
209за 3 месяца
44за месяц
0за неделю

Данные обновлены 20.08.2026 · по Москве

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 168

Высокая CVSS 8.6

CVE-2026-75948

РасширениеiCagenda
Разработчикicagenda.com

Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.

20.08.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-75956

Разработчикcmsjunkie.com

DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP…

19.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-75954

Разработчикcmsjunkie.com

SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-75949

Разработчикcmsjunkie.com

Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees)…

19.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74804

Разработчикyootheme.com

Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.ty…

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74803

Разработчикyootheme.com

Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-67364

Разработчикbalbooa.com

Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handle…

19.08.2026 Требует внимания
Высокая CVSS 7.7

CVE-2026-67363

Разработчикbalbooa.com

Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it…

19.08.2026 Требует внимания
Высокая CVSS 8.9

CVE-2026-73373

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that execute…

18.08.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-73337

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

18.08.2026 Требует внимания
Высокая CVSS 8.5

CVE-2026-71574

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform muta…

18.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74254

Разработчикjoomlack.fr

SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the fro…

17.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74253

Разработчикregularlabs.com

Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML with…

17.08.2026 Требует внимания
Критическая CVSS 9.3

CVE-2026-74251

РасширениеPhoca Cart
Разработчикphoca.cz

Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are co…

16.08.2026 Требует внимания
Высокая CVSS 8.6

CVE-2026-71571

Разработчикicagenda.com

Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

14.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-67365

Разработчикicagenda.com

Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

14.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-67285

Разработчикjoomshaper.com

Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.

12.08.2026 Требует внимания