Filtered by vendor Joomla
Subscribe
Total
975 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-48899 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper access check allows privilege escalation through the com_users batch task. | |||||
| CVE-2026-48898 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper access check allows privilege escalation through the com_users batch task. | |||||
| CVE-2026-48897 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 7.5 HIGH |
| Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |||||
| CVE-2026-48896 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 7.5 HIGH |
| Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |||||
| CVE-2026-40384 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 7.5 HIGH |
| An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | |||||
| CVE-2026-40383 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper validation of user-supplied input leads to a local file inclusion vulnerability. | |||||
| CVE-2026-35223 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper access check allows unauthorized access to com_config webservice endpoints. | |||||
| CVE-2026-35222 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | |||||
| CVE-2026-35221 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | |||||
| CVE-2026-30895 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Lack of output escaping leads to a XSS vector in the readmore links for com_content. | |||||
| CVE-2026-30894 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Lack of output escaping leads to a XSS vector in the content history component. | |||||
| CVE-2026-25901 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Lack of output escaping leads to a XSS vector in the multilingual associations component. | |||||
| CVE-2026-23899 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 8.8 HIGH |
| An improper access check allows unauthorized access to webservice endpoints. | |||||
| CVE-2026-23898 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 7.2 HIGH |
| Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. | |||||
| CVE-2026-21632 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 5.4 MEDIUM |
| Lack of output escaping for article titles leads to XSS vectors in various locations. | |||||
| CVE-2026-21631 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 5.4 MEDIUM |
| Lack of output escaping leads to a XSS vector in the multilingual associations component. | |||||
| CVE-2026-21630 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 8.8 HIGH |
| Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. | |||||
| CVE-2026-21629 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 7.3 HIGH |
| The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers. | |||||
| CVE-2025-63083 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Lack of output escaping leads to a XSS vector in the pagebreak plugin. | |||||
| CVE-2025-63082 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. | |||||
