VYPR

Bitnami package

joomla

pkg:bitnami/joomla

Vulnerabilities (134)

  • CVE-2026-48958HigJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    An improper access check allows unauthorized users to create custom fields via webservices endpoints.

  • CVE-2026-48957HigJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    An improper access check allows unauthorized users to access com_privacy datasets.

  • CVE-2026-48956MedJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    An improper access check allows users to display a list of modules in the frontend.

  • CVE-2026-48955MedJul 7, 2026
    affected >= 6.0.0, < 6.1.2fixed 6.1.2

    An improper access check allows unauthorized users to access workflow stage and transition information.

  • CVE-2026-48954MedJul 7, 2026
    affected >= 3.0.0, < 5.4.7fixed 5.4.7

    Improper validation leads to a generic XSS vector in the language override feature.

  • CVE-2026-48953MedJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    Lack of escaping leads to an XSS vulnerability in the generic image output layout.

  • CVE-2026-48952MedJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

  • CVE-2026-48951MedJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

  • CVE-2026-48950MedJul 7, 2026
    affected >= 4.0.0, < 5.4.7fixed 5.4.7

    Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

  • CVE-2026-48949MedJul 7, 2026
    affected >= 4.2.0, < 5.4.7fixed 5.4.7

    Lack of validation leads to an XSS vulnerability in the MFA management views.

  • CVE-2026-48948HigJul 7, 2026
    affected >= 3.0.0, < 5.4.7fixed 5.4.7

    An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

  • CVE-2026-48947MedJul 7, 2026
    affected >= 4.1.0, < 5.4.7fixed 5.4.7

    An improper access check allows privileged users to overwrite media files without editing permissions.

  • CVE-2026-48905MedMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Lack of input filtering leads to an XSS vector in the HTML filter code.

  • CVE-2026-48904CriMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

  • CVE-2026-48903MedMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

  • CVE-2026-48902CriMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

  • CVE-2026-48901HigMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

  • CVE-2026-48900MedMay 26, 2026
    affected >= 4.1.0, < 5.4.6fixed 5.4.6

    An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

  • CVE-2026-48899CriMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    An improper access check allows privilege escalation through the com_users batch task.

  • CVE-2026-48898CriMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    An improper access check allows privilege escalation through the com_users batch task.

Page 1 of 7