Skip to main content

Vendor/product archive

joomla / joomla! CVEs

Beta · best-effort

642 CVEs tagged to joomla / joomla!34 Critical, 281 High, 323 Medium, 4 Low, 0 Unrated.

CVE-2026-48958

Published Jul 7, 2026

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48957

Published Jul 7, 2026

An improper access check allows unauthorized users to access com_privacy datasets.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48956

Published Jul 7, 2026

An improper access check allows users to display a list of modules in the frontend.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48955

Published Jul 7, 2026

An improper access check allows unauthorized users to access workflow stage and transition information.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48954

Published Jul 7, 2026

Improper validation leads to a generic XSS vector in the language override feature.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48953

Published Jul 7, 2026

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48952

Published Jul 7, 2026

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48951

Published Jul 7, 2026

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48950

Published Jul 7, 2026

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48949

Published Jul 7, 2026

Lack of validation leads to an XSS vulnerability in the MFA management views.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48948

Published Jul 7, 2026

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48947

Published Jul 7, 2026

An improper access check allows privileged users to overwrite media files without editing permissions.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48905

Published May 26, 2026

Lack of input filtering leads to an XSS vector in the HTML filter code.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48904

Published May 26, 2026

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48903

Published May 26, 2026

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48902

Published May 26, 2026

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48901

Published May 26, 2026

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48900

Published May 26, 2026

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48899

Published May 26, 2026

An improper access check allows privilege escalation through the com_users batch task.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48898

Published May 26, 2026

An improper access check allows privilege escalation through the com_users batch task.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48897

Published May 26, 2026

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48896

Published May 26, 2026

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40384

Published May 26, 2026

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40383

Published May 26, 2026

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35223

Published May 26, 2026

An improper access check allows unauthorized access to com_config webservice endpoints.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 642 CVEsPage 1 of 26