Каталог CVE

Разработчик: developer.joomla

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 159

Разработчик: developer.joomla
Средняя CVSS 5.1

CVE-2026-73372

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unacc…

18.08.2026 Активна
Средняя CVSS 5.1

CVE-2026-73336

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

18.08.2026 Активна
Средняя CVSS 5.1

CVE-2026-72531

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fiel…

18.08.2026 Активна
Средняя CVSS 6.9

CVE-2026-71573

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated i…

18.08.2026 Активна
Средняя CVSS 4.8

CVE-2026-71572

Расширениеdownload views in Joomla
Разработчикdeveloper.joomla

Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download vi…

18.08.2026 Активна
Высокая CVSS 8.9

CVE-2026-73373

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that execute…

18.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-73371

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operatio…

18.08.2026 Активна
Высокая CVSS 8.2

CVE-2026-73337

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

18.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-72532

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categorie…

18.08.2026 Активна
Высокая CVSS 8.5

CVE-2026-71574

РасширениеJoomla
Разработчикdeveloper.joomla

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform muta…

18.08.2026 Требует внимания
Средняя CVSS 6.1

CVE-2023-23754

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

30.05.2023
Средняя CVSS 6.3

CVE-2023-23750

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.

01.02.2023
Средняя CVSS 6.1

CVE-2022-27914

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.

08.11.2022
Средняя CVSS 6.1

CVE-2022-27913

РасширениеJoomla Joomla\!
Разработчикdeveloper.joomla

An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

25.10.2022