| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. |
| Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. |
| Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. |
| Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. |
| Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. |
| Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| Improper validation leads to a generic XSS vector in the language override feature. |
| Lack of validation leads to an XSS vulnerability in the MFA management views. |
| An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
| Lack of escaping leads to an XSS vulnerability in the generic image output layout. |
| Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. |
| An improper access check allows unauthorized users to access com_privacy datasets. |
| An improper access check allows users to display a list of modules in the frontend. |
| An improper access check allows unauthorized users to access workflow stage and transition information. |
| Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. |
| An improper access check allows unauthorized users to create custom fields via webservices endpoints. |
| An improper access check allows privileged users to overwrite media files without editing permissions. |
| Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. |
| Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. |
| Lack of output escaping leads to a XSS vector in the content history component. |