Bitnami package
joomla
pkg:bitnami/joomla
Vulnerabilities (134)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48897 | Hig | 7.5 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| CVE-2026-48896 | Hig | 7.5 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| CVE-2026-40384 | Hig | 7.5 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | |
| CVE-2026-40383 | Cri | 9.8 | >= 3.2.1, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. | |
| CVE-2026-35223 | Cri | 9.8 | >= 4.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. | |
| CVE-2026-35222 | Cri | 9.8 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | |
| CVE-2026-35221 | Cri | 9.8 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | |
| CVE-2026-35220 | Med | 4.3 | >= 6.0.0, < 6.1.1 | 6.1.1 | May 26, 2026 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. | |
| CVE-2026-30895 | Med | 6.1 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | |
| CVE-2026-30894 | Med | 6.1 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the content history component. | |
| CVE-2026-25901 | Med | 6.1 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | |
| CVE-2026-25900 | Med | 6.1 | >= 3.0.0, < 5.4.6 | 5.4.6 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the feed modules. | |
| CVE-2026-23899 | Hig | 8.8 | >= 3.0.0, < 5.4.4 | 5.4.4 | Apr 1, 2026 | An improper access check allows unauthorized access to webservice endpoints. | |
| CVE-2026-23898 | Hig | 7.2 | >= 3.0.0, < 5.4.4 | 5.4.4 | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. | |
| CVE-2026-21632 | Med | 5.4 | >= 3.0.0, < 5.4.4 | 5.4.4 | Apr 1, 2026 | Lack of output escaping for article titles leads to XSS vectors in various locations. | |
| CVE-2026-21631 | Med | 5.4 | >= 3.0.0, < 5.4.4 | 5.4.4 | Apr 1, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | |
| CVE-2026-21630 | Hig | 8.8 | >= 3.0.0, < 5.4.4 | 5.4.4 | Apr 1, 2026 | Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. | |
| CVE-2026-21629 | Hig | 7.3 | >= 3.0.0, < 5.4.4 | 5.4.4 | Apr 1, 2026 | The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers. | |
| CVE-2025-63083 | Med | 6.1 | >= 3.9.0, < 5.4.2 | 5.4.2 | Jan 6, 2026 | Lack of output escaping leads to a XSS vector in the pagebreak plugin. | |
| CVE-2025-63082 | Med | 6.1 | >= 4.0.0, < 5.4.2 | 5.4.2 | Jan 6, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. |
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
- affected >= 3.2.1, < 5.4.6fixed 5.4.6
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
- affected >= 4.0.0, < 5.4.6fixed 5.4.6
An improper access check allows unauthorized access to com_config webservice endpoints.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
- affected >= 6.0.0, < 6.1.1fixed 6.1.1
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Lack of output escaping leads to a XSS vector in the content history component.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Lack of output escaping leads to a XSS vector in the multilingual associations component.
- affected >= 3.0.0, < 5.4.6fixed 5.4.6
Lack of output escaping leads to a XSS vector in the feed modules.
- affected >= 3.0.0, < 5.4.4fixed 5.4.4
An improper access check allows unauthorized access to webservice endpoints.
- affected >= 3.0.0, < 5.4.4fixed 5.4.4
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
- affected >= 3.0.0, < 5.4.4fixed 5.4.4
Lack of output escaping for article titles leads to XSS vectors in various locations.
- affected >= 3.0.0, < 5.4.4fixed 5.4.4
Lack of output escaping leads to a XSS vector in the multilingual associations component.
- affected >= 3.0.0, < 5.4.4fixed 5.4.4
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
- affected >= 3.0.0, < 5.4.4fixed 5.4.4
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
- affected >= 3.9.0, < 5.4.2fixed 5.4.2
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
- affected >= 4.0.0, < 5.4.2fixed 5.4.2
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
Page 2 of 7