Filtered by vendor Joomla
Subscribe
Total
975 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-48955 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.5 MEDIUM |
| An improper access check allows unauthorized users to access workflow stage and transition information. | |||||
| CVE-2026-48956 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 5.0 MEDIUM |
| An improper access check allows users to display a list of modules in the frontend. | |||||
| CVE-2026-48957 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 8.8 HIGH |
| An improper access check allows unauthorized users to access com_privacy datasets. | |||||
| CVE-2026-48958 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 8.8 HIGH |
| An improper access check allows unauthorized users to create custom fields via webservices endpoints. | |||||
| CVE-2026-48954 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Improper validation leads to a generic XSS vector in the language override feature. | |||||
| CVE-2026-48947 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 4.9 MEDIUM |
| An improper access check allows privileged users to overwrite media files without editing permissions. | |||||
| CVE-2026-48948 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 8.8 HIGH |
| An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | |||||
| CVE-2026-48949 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of validation leads to an XSS vulnerability in the MFA management views. | |||||
| CVE-2026-48950 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | |||||
| CVE-2026-48951 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | |||||
| CVE-2026-48952 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | |||||
| CVE-2026-48953 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to an XSS vulnerability in the generic image output layout. | |||||
| CVE-2026-48905 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Lack of input filtering leads to an XSS vector in the HTML filter code. | |||||
| CVE-2026-48904 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | |||||
| CVE-2026-48903 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 6.1 MEDIUM |
| Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | |||||
| CVE-2026-48902 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | |||||
| CVE-2026-48901 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 7.5 HIGH |
| The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | |||||
| CVE-2026-48900 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 4.3 MEDIUM |
| An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. | |||||
| CVE-2026-48899 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper access check allows privilege escalation through the com_users batch task. | |||||
| CVE-2026-48898 | 1 Joomla | 1 Joomla\! | 2026-06-17 | N/A | 9.8 CRITICAL |
| An improper access check allows privilege escalation through the com_users batch task. | |||||
