Vendor CVEs
Joomla
All CVEs
1,291 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65430 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability. | ||
| CVE-2026-64876 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates. | ||
| CVE-2026-64874 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. | ||
| CVE-2026-64873 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | ||
| CVE-2026-64872 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory. | ||
| CVE-2026-64871 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission. | ||
| CVE-2026-64799 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they… | ||
| CVE-2026-64798 | Cri | 0.00 | 9.1 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. | ||
| CVE-2026-64797 | Hig | 0.00 | 7.5 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts. | ||
| CVE-2026-64796 | Cri | 0.00 | 9.8 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP… | ||
| CVE-2026-64794 | Med | 0.00 | 6.5 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user… | ||
| CVE-2026-64793 | Cri | 0.00 | 9.1 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby… | ||
| CVE-2026-63685 | Hig | 0.00 | 8.8 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database… | ||
| CVE-2026-63280 | Hig | 0.00 | 8.8 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions. | ||
| CVE-2026-63047 | Hig | 0.00 | 7.5 | 0.00 | Jul 22, 2026 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. | ||
| CVE-2026-62415 | Cri | 0.00 | 9.1 | 0.00 | Jul 21, 2026 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. | ||
| CVE-2026-61901 | Med | 0.00 | 6.1 | 0.00 | Jul 20, 2026 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect. | ||
| CVE-2026-61425 | Cri | 0.00 | — | 0.01 | Jul 20, 2026 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | ||
| CVE-2026-61424 | Cri | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | ||
| CVE-2026-60034 | Cri | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS. | ||
| CVE-2026-60033 | Med | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses. | ||
| CVE-2026-60032 | Cri | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip… | ||
| CVE-2026-60031 | Med | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses. | ||
| CVE-2026-60030 | Hig | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management… | ||
| CVE-2026-60029 | Med | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for… | ||
| CVE-2026-60028 | Hig | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin… | ||
| CVE-2026-60027 | Hig | 0.00 | — | 0.01 | Jul 20, 2026 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed… | ||
| CVE-2026-60026 | Hig | 0.00 | — | 0.01 | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in… | ||
| CVE-2026-60025 | Hig | 0.00 | 8.8 | 0.00 | Jul 17, 2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | ||
| CVE-2026-60024 | Cri | 0.00 | 9.8 | 0.01 | Jul 17, 2026 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. | ||
| CVE-2026-58149 | Med | 0.00 | 5.3 | 0.00 | Jul 17, 2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses. | ||
| CVE-2026-58148 | Hig | 0.00 | — | 0.00 | Jul 17, 2026 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability. | ||
| CVE-2026-58078 | Hig | 0.00 | — | 0.00 | Jul 16, 2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection. | ||
| CVE-2026-57832 | Hig | 0.00 | — | 0.00 | Jul 15, 2026 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection. | ||
| CVE-2026-57831 | Hig | 0.00 | — | 0.00 | Jul 15, 2026 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection. | ||
| CVE-2026-57830 | Cri | 0.00 | 9.1 | 0.01 | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. | ||
| CVE-2026-57829 | Med | 0.00 | 6.1 | 0.00 | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. | ||
| CVE-2026-57827 | Cri | 0.00 | 9.8 | 0.02 | Jul 11, 2026 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | ||
| CVE-2026-48958 | Hig | 0.00 | 8.8 | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | ||
| CVE-2026-48957 | Hig | 0.00 | 8.8 | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to access com_privacy datasets. | ||
| CVE-2026-48956 | Med | 0.00 | 5.0 | 0.00 | Jul 7, 2026 | An improper access check allows users to display a list of modules in the frontend. | ||
| CVE-2026-48955 | Med | 0.00 | 6.5 | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. | ||
| CVE-2026-48954 | Med | 0.00 | 6.1 | 0.00 | Jul 7, 2026 | Improper validation leads to a generic XSS vector in the language override feature. | ||
| CVE-2026-48953 | Med | 0.00 | 6.1 | 0.00 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. | ||
| CVE-2026-48952 | Med | 0.00 | 6.1 | 0.00 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | ||
| CVE-2026-48951 | Med | 0.00 | 6.1 | 0.00 | Jul 7, 2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | ||
| CVE-2026-48950 | Med | 0.00 | 6.1 | 0.00 | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | ||
| CVE-2026-48949 | Med | 0.00 | 6.1 | 0.00 | Jul 7, 2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. | ||
| CVE-2026-48948 | Hig | 0.00 | 8.8 | 0.00 | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | ||
| CVE-2026-48947 | Med | 0.00 | 4.9 | 0.00 | Jul 7, 2026 | An improper access check allows privileged users to overwrite media files without editing permissions. |
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
- risk 0.00cvss 8.8epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.
- risk 0.00cvss 5.4epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they…
- risk 0.00cvss 9.1epss 0.00
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP…
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user…
- risk 0.00cvss 9.1epss 0.00
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby…
- risk 0.00cvss 8.8epss 0.00
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database…
- risk 0.00cvss 8.8epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
- risk 0.00cvss 9.1epss 0.00
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
- risk 0.00cvss 6.1epss 0.00
Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.
- risk 0.00cvss —epss 0.01
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
- risk 0.00cvss —epss 0.00
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip…
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management…
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for…
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin…
- risk 0.00cvss —epss 0.01
Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed…
- risk 0.00cvss —epss 0.01
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in…
- risk 0.00cvss 8.8epss 0.00
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
- risk 0.00cvss 9.8epss 0.01
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
- risk 0.00cvss 5.3epss 0.00
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
- risk 0.00cvss —epss 0.00
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.
- risk 0.00cvss —epss 0.00
Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
- risk 0.00cvss —epss 0.00
Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
- risk 0.00cvss 9.1epss 0.01
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
- risk 0.00cvss 6.1epss 0.00
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
- risk 0.00cvss 9.8epss 0.02
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
- risk 0.00cvss 8.8epss 0.00
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
- risk 0.00cvss 8.8epss 0.00
An improper access check allows unauthorized users to access com_privacy datasets.
- risk 0.00cvss 5.0epss 0.00
An improper access check allows users to display a list of modules in the frontend.
- risk 0.00cvss 6.5epss 0.00
An improper access check allows unauthorized users to access workflow stage and transition information.
- risk 0.00cvss 6.1epss 0.00
Improper validation leads to a generic XSS vector in the language override feature.
- risk 0.00cvss 6.1epss 0.00
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
- risk 0.00cvss 6.1epss 0.00
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
- risk 0.00cvss 6.1epss 0.00
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
- risk 0.00cvss 6.1epss 0.00
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
- risk 0.00cvss 6.1epss 0.00
Lack of validation leads to an XSS vulnerability in the MFA management views.
- risk 0.00cvss 8.8epss 0.00
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
- risk 0.00cvss 4.9epss 0.00
An improper access check allows privileged users to overwrite media files without editing permissions.
Page 22 of 26