Joomla! Core
by Joomla
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48952 | 0.00 | — | 0.00 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | |||
| CVE-2026-48958 | 0.00 | — | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | |||
| CVE-2026-48950 | 0.00 | — | 0.00 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | |||
| CVE-2026-48955 | 0.00 | — | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. | |||
| CVE-2026-48957 | 0.00 | — | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to access com_privacy datasets. | |||
| CVE-2026-48951 | 0.00 | — | 0.00 | Jul 7, 2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | |||
| CVE-2026-48953 | 0.00 | — | 0.00 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. | |||
| CVE-2026-48948 | 0.00 | — | 0.00 | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | |||
| CVE-2026-48949 | 0.00 | — | 0.00 | Jul 7, 2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. | |||
| CVE-2026-48954 | 0.00 | — | 0.00 | Jul 7, 2026 | Improper validation leads to a generic XSS vector in the language override feature. |
- CVE-2026-48952Jul 7, 2026risk 0.00cvss —epss 0.00
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
- CVE-2026-48958Jul 7, 2026risk 0.00cvss —epss 0.00
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
- CVE-2026-48950Jul 7, 2026risk 0.00cvss —epss 0.00
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
- CVE-2026-48955Jul 7, 2026risk 0.00cvss —epss 0.00
An improper access check allows unauthorized users to access workflow stage and transition information.
- CVE-2026-48957Jul 7, 2026risk 0.00cvss —epss 0.00
An improper access check allows unauthorized users to access com_privacy datasets.
- CVE-2026-48951Jul 7, 2026risk 0.00cvss —epss 0.00
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
- CVE-2026-48953Jul 7, 2026risk 0.00cvss —epss 0.00
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
- CVE-2026-48948Jul 7, 2026risk 0.00cvss —epss 0.00
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
- CVE-2026-48949Jul 7, 2026risk 0.00cvss —epss 0.00
Lack of validation leads to an XSS vulnerability in the MFA management views.
- CVE-2026-48954Jul 7, 2026risk 0.00cvss —epss 0.00
Improper validation leads to a generic XSS vector in the language override feature.