Vulnerabilities (CVE)

Filtered by vendor Joomla Subscribe
Total 975 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-48899 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48897 1 Joomla 1 Joomla\! 2026-06-17 N/A 7.5 HIGH
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48896 1 Joomla 1 Joomla\! 2026-06-17 N/A 7.5 HIGH
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-40384 1 Joomla 1 Joomla\! 2026-06-17 N/A 7.5 HIGH
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
CVE-2026-40383 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-35223 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper access check allows unauthorized access to com_config webservice endpoints.
CVE-2026-35222 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-35221 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
CVE-2026-30895 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVE-2026-30894 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-25901 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-23899 1 Joomla 1 Joomla\! 2026-06-17 N/A 8.8 HIGH
An improper access check allows unauthorized access to webservice endpoints.
CVE-2026-23898 1 Joomla 1 Joomla\! 2026-06-17 N/A 7.2 HIGH
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
CVE-2026-21632 1 Joomla 1 Joomla\! 2026-06-17 N/A 5.4 MEDIUM
Lack of output escaping for article titles leads to XSS vectors in various locations.
CVE-2026-21631 1 Joomla 1 Joomla\! 2026-06-17 N/A 5.4 MEDIUM
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-21630 1 Joomla 1 Joomla\! 2026-06-17 N/A 8.8 HIGH
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
CVE-2026-21629 1 Joomla 1 Joomla\! 2026-06-17 N/A 7.3 HIGH
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
CVE-2025-63083 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVE-2025-63082 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.