Search Results (669 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-71573 1 Joomla 2 Joomla!, Joomla\! 2026-09-03 8.3 High
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
CVE-2026-72531 1 Joomla 2 Joomla!, Joomla\! 2026-09-03 5.4 Medium
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
CVE-2026-73336 1 Joomla 2 Joomla!, Joomla\! 2026-09-03 6.4 Medium
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
CVE-2026-73372 1 Joomla 2 Joomla!, Joomla\! 2026-09-03 4.3 Medium
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
CVE-2026-73371 1 Joomla 2 Joomla!, Joomla\! 2026-09-03 4.3 Medium
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
CVE-2026-73337 1 Joomla 2 Joomla!, Joomla\! 2026-09-03 7.5 High
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48954 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Improper validation leads to a generic XSS vector in the language override feature.
CVE-2026-48949 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48948 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 8.8 High
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-48953 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48951 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48957 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 8.8 High
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48956 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 5.0 Medium
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48955 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.5 Medium
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48950 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48958 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 8.8 High
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48947 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 4.9 Medium
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48952 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-35222 1 Joomla 2 Joomla!, Joomla\! 2026-06-02 9.8 Critical
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-30894 1 Joomla 2 Joomla!, Joomla\! 2026-06-02 6.1 Medium
Lack of output escaping leads to a XSS vector in the content history component.