Bitnami package
joomla
pkg:bitnami/joomla
Vulnerabilities (160)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-92232 | Med | 6.5 | >= 1.5.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an | |
| CVE-2026-92231 | Med | 6.7 | >= 1.5.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTM | |
| CVE-2026-92227 | Hig | 7.5 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability. | |
| CVE-2026-92226 | Med | 6.0 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items. | |
| CVE-2026-92225 | Med | 6.7 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector. | |
| CVE-2026-92224 | Med | 6.7 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector. | |
| CVE-2026-92223 | Low | 3.8 | >= 5.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents. | |
| CVE-2026-92222 | Hig | 8.0 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors. | |
| CVE-2026-90918 | Med | 5.3 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | |
| CVE-2026-90917 | Med | 5.3 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories. | |
| CVE-2026-90916 | Low | 2.7 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents. | |
| CVE-2026-90915 | Med | 6.5 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions. | |
| CVE-2026-90914 | Med | 6.4 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts. | |
| CVE-2026-90913 | Med | 5.5 | >= 4.0.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints. | |
| CVE-2026-90907 | Med | 5.3 | >= 1.5.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user regi | |
| CVE-2026-90906 | Hig | 8.3 | >= 1.5.0, < 5.4.8 | 5.4.8 | Sep 29, 2026 | Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper. | |
| CVE-2026-73372 | Med | 4.3 | >= 5.1.0, < 5.4.8 | 5.4.8 | Aug 18, 2026 | Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. | |
| CVE-2026-73336 | Med | 6.4 | >= 5.1.0, < 5.4.8 | 5.4.8 | Aug 18, 2026 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | |
| CVE-2026-72531 | Med | 5.4 | >= 4.0.0, < 5.4.8 | 5.4.8 | Aug 18, 2026 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | |
| CVE-2026-71573 | Hig | 8.3 | >= 4.0.0, < 5.4.8 | 5.4.8 | Aug 18, 2026 | Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. |
- affected >= 1.5.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an
- affected >= 1.5.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTM
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.
- affected >= 5.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints.
- affected >= 1.5.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user regi
- affected >= 1.5.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper.
- affected >= 5.1.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
- affected >= 5.1.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
- affected >= 4.0.0, < 5.4.8fixed 5.4.8
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
Page 1 of 8