Каталог CVE

Разработчик: themexpert.com

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 10

Разработчик: themexpert.com
Критическая CVSS 9.4

CVE-2026-60034

Разработчикthemexpert.com

Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to st…

20.07.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-60033

Разработчикthemexpert.com

SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.

20.07.2026 Активна
Критическая CVSS 9.4

CVE-2026-60032

Разработчикthemexpert.com

Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possib…

20.07.2026 Требует внимания
Средняя CVSS 6.9

CVE-2026-60031

Разработчикthemexpert.com

Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler respons…

20.07.2026 Активна
Высокая CVSS 8.7

CVE-2026-60030

Разработчикthemexpert.com

Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could u…

20.07.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-60029

Разработчикthemexpert.com

Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users co…

20.07.2026 Активна
Высокая CVSS 8.6

CVE-2026-60028

Разработчикthemexpert.com

Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user cou…

20.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-60027

Разработчикthemexpert.com

Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Una…

20.07.2026 Требует внимания
Высокая CVSS 8.9

CVE-2026-60026

Разработчикthemexpert.com

Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (…

20.07.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-58078

Разработчикthemexpert.com

Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

16.07.2026 Требует внимания