Bitnami package
joomla
pkg:bitnami/joomla
Vulnerabilities (134)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48958 | Hig | 8.8 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | |
| CVE-2026-48957 | Hig | 8.8 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | An improper access check allows unauthorized users to access com_privacy datasets. | |
| CVE-2026-48956 | Med | 5.0 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | An improper access check allows users to display a list of modules in the frontend. | |
| CVE-2026-48955 | Med | 6.5 | >= 6.0.0, < 6.1.2 | 6.1.2 | Jul 7, 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. | |
| CVE-2026-48954 | Med | 6.1 | >= 3.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | Improper validation leads to a generic XSS vector in the language override feature. | |
| CVE-2026-48953 | Med | 6.1 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. | |
| CVE-2026-48952 | Med | 6.1 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | |
| CVE-2026-48951 | Med | 6.1 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | |
| CVE-2026-48950 | Med | 6.1 | >= 4.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | |
| CVE-2026-48949 | Med | 6.1 | >= 4.2.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. | |
| CVE-2026-48948 | Hig | 8.8 | >= 3.0.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | |
| CVE-2026-48947 | Med | 4.9 | >= 4.1.0, < 5.4.7 | 5.4.7 | Jul 7, 2026 | An improper access check allows privileged users to overwrite media files without editing permissions. | |
| CVE-2026-48905 | Med | 6.1 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. | |
| CVE-2026-48904 | Cri | 9.8 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | |
| CVE-2026-48903 | Med | 6.1 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | |
| CVE-2026-48902 | Cri | 9.8 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | |
| CVE-2026-48901 | Hig | 7.5 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | |
| CVE-2026-48900 | Med | 4.3 | >= 4.1.0, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. | |
| CVE-2026-48899 | Cri | 9.8 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. | |
| CVE-2026-48898 | Cri | 9.8 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
An improper access check allows unauthorized users to access com_privacy datasets.
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
An improper access check allows users to display a list of modules in the frontend.
- affected >= 6.0.0, < 6.1.2fixed 6.1.2
An improper access check allows unauthorized users to access workflow stage and transition information.
- affected >= 3.0.0, < 5.4.7fixed 5.4.7
Improper validation leads to a generic XSS vector in the language override feature.
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
- affected >= 4.0.0, < 5.4.7fixed 5.4.7
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
- affected >= 4.2.0, < 5.4.7fixed 5.4.7
Lack of validation leads to an XSS vulnerability in the MFA management views.
- affected >= 3.0.0, < 5.4.7fixed 5.4.7
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
- affected >= 4.1.0, < 5.4.7fixed 5.4.7
An improper access check allows privileged users to overwrite media files without editing permissions.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Lack of input filtering leads to an XSS vector in the HTML filter code.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
- affected >= 4.1.0, < 5.4.6fixed 5.4.6
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
An improper access check allows privilege escalation through the com_users batch task.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
An improper access check allows privilege escalation through the com_users batch task.
Page 1 of 7