VYPR

com_joomlaupdate

by Joomla

Source repositories

CVEs (2)

  • CVE-2019-12764MedJun 11, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.

  • CVE-2026-23898HigApr 1, 2026
    risk 0.40cvss 7.2epss 0.00

    Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.