VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2026-65430HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

  • CVE-2026-64876HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.

  • CVE-2026-64874CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

  • CVE-2026-64873CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

  • CVE-2026-64872MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

  • CVE-2026-64871MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

  • CVE-2026-64799HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they…

  • CVE-2026-64798CriJul 22, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

  • CVE-2026-64797HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

  • CVE-2026-64796CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP…

  • CVE-2026-64794MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user…

  • CVE-2026-64793CriJul 22, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby…

  • CVE-2026-63685HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database…

  • CVE-2026-63280HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

  • CVE-2026-63047HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

  • CVE-2026-62415CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

  • CVE-2026-61901MedJul 20, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

  • CVE-2026-61425CriJul 20, 2026
    risk 0.00cvss —epss 0.01

    Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

  • CVE-2026-61424CriJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

  • CVE-2026-60034CriJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.

  • CVE-2026-60033MedJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.

  • CVE-2026-60032CriJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip…

  • CVE-2026-60031MedJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

  • CVE-2026-60030HigJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management…

  • CVE-2026-60029MedJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for…

  • CVE-2026-60028HigJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin…

  • CVE-2026-60027HigJul 20, 2026
    risk 0.00cvss —epss 0.01

    Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed…

  • CVE-2026-60026HigJul 20, 2026
    risk 0.00cvss —epss 0.01

    Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in…

  • CVE-2026-60025HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

  • CVE-2026-60024CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

  • CVE-2026-58149MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.

  • CVE-2026-58148HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

  • CVE-2026-58078HigJul 16, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

  • CVE-2026-57832HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.

  • CVE-2026-57831HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.

  • CVE-2026-57830CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

  • CVE-2026-57829MedJul 13, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

  • CVE-2026-57827CriJul 11, 2026
    risk 0.00cvss 9.8epss 0.02

    Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

  • CVE-2026-48958HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows unauthorized users to create custom fields via webservices endpoints.

  • CVE-2026-48957HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows unauthorized users to access com_privacy datasets.

  • CVE-2026-48956MedJul 7, 2026
    risk 0.00cvss 5.0epss 0.00

    An improper access check allows users to display a list of modules in the frontend.

  • CVE-2026-48955MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.00

    An improper access check allows unauthorized users to access workflow stage and transition information.

  • CVE-2026-48954MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper validation leads to a generic XSS vector in the language override feature.

  • CVE-2026-48953MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to an XSS vulnerability in the generic image output layout.

  • CVE-2026-48952MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

  • CVE-2026-48951MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

  • CVE-2026-48950MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

  • CVE-2026-48949MedJul 7, 2026
    risk 0.00cvss 6.1epss 0.00

    Lack of validation leads to an XSS vulnerability in the MFA management views.

  • CVE-2026-48948HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

  • CVE-2026-48947MedJul 7, 2026
    risk 0.00cvss 4.9epss 0.00

    An improper access check allows privileged users to overwrite media files without editing permissions.

Page 22 of 26