Vulnerabilities (CVE)

Filtered by vendor Joomla Subscribe
Total 975 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-48955 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.5 MEDIUM
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48956 1 Joomla 1 Joomla\! 2026-07-09 N/A 5.0 MEDIUM
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48957 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48958 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48954 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Improper validation leads to a generic XSS vector in the language override feature.
CVE-2026-48947 1 Joomla 1 Joomla\! 2026-07-09 N/A 4.9 MEDIUM
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48948 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-48949 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48950 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48951 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48952 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48953 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48905 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48904 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48903 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48902 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVE-2026-48901 1 Joomla 1 Joomla\! 2026-06-17 N/A 7.5 HIGH
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48900 1 Joomla 1 Joomla\! 2026-06-17 N/A 4.3 MEDIUM
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-48899 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898 1 Joomla 1 Joomla\! 2026-06-17 N/A 9.8 CRITICAL
An improper access check allows privilege escalation through the com_users batch task.