VYPR

Bitnami package

joomla

pkg:bitnami/joomla

Vulnerabilities (134)

  • CVE-2026-48897HigMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2026-48896HigMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2026-40384HigMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

  • CVE-2026-40383CriMay 26, 2026
    affected >= 3.2.1, < 5.4.6fixed 5.4.6

    An improper validation of user-supplied input leads to a local file inclusion vulnerability.

  • CVE-2026-35223CriMay 26, 2026
    affected >= 4.0.0, < 5.4.6fixed 5.4.6

    An improper access check allows unauthorized access to com_config webservice endpoints.

  • CVE-2026-35222CriMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

  • CVE-2026-35221CriMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

  • CVE-2026-35220MedMay 26, 2026
    affected >= 6.0.0, < 6.1.1fixed 6.1.1

    Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

  • CVE-2026-30895MedMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Lack of output escaping leads to a XSS vector in the readmore links for com_content.

  • CVE-2026-30894MedMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Lack of output escaping leads to a XSS vector in the content history component.

  • CVE-2026-25901MedMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Lack of output escaping leads to a XSS vector in the multilingual associations component.

  • CVE-2026-25900MedMay 26, 2026
    affected >= 3.0.0, < 5.4.6fixed 5.4.6

    Lack of output escaping leads to a XSS vector in the feed modules.

  • CVE-2026-23899HigApr 1, 2026
    affected >= 3.0.0, < 5.4.4fixed 5.4.4

    An improper access check allows unauthorized access to webservice endpoints.

  • CVE-2026-23898HigApr 1, 2026
    affected >= 3.0.0, < 5.4.4fixed 5.4.4

    Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

  • CVE-2026-21632MedApr 1, 2026
    affected >= 3.0.0, < 5.4.4fixed 5.4.4

    Lack of output escaping for article titles leads to XSS vectors in various locations.

  • CVE-2026-21631MedApr 1, 2026
    affected >= 3.0.0, < 5.4.4fixed 5.4.4

    Lack of output escaping leads to a XSS vector in the multilingual associations component.

  • CVE-2026-21630HigApr 1, 2026
    affected >= 3.0.0, < 5.4.4fixed 5.4.4

    Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

  • CVE-2026-21629HigApr 1, 2026
    affected >= 3.0.0, < 5.4.4fixed 5.4.4

    The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.

  • CVE-2025-63083MedJan 6, 2026
    affected >= 3.9.0, < 5.4.2fixed 5.4.2

    Lack of output escaping leads to a XSS vector in the pagebreak plugin.

  • CVE-2025-63082MedJan 6, 2026
    affected >= 4.0.0, < 5.4.2fixed 5.4.2

    Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

Page 2 of 7