Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-48957 An improper access check allows unauthorized users to access com_privacy datasets. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-48958 An improper access check allows unauthorized users to create custom fields via webservices endpoints. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,9502026-07-07 MEDIUM 6.5 CVE-2026-48955 An improper access check allows unauthorized users to access workflow stage and transition information. Joomla\! 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48954 Improper validation leads to a generic XSS vector in the language override feature. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 5.0 CVE-2026-48956 An improper access check allows users to display a list of modules in the frontend. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48949 Lack of validation leads to an XSS vulnerability in the MFA management views. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48950 Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48951 Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48952 Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 MEDIUM 6.1 CVE-2026-48953 Lack of escaping leads to an XSS vulnerability in the generic image output layout. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,6002026-07-07 HIGH 8.8 CVE-2026-48948 An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. Joomla\! 5.4.7 / 6.1.2+ Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-48904 An improper access check allows privelege escalation through the com_users group editing webservice endpoint. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 MEDIUM 6.1 CVE-2026-48903 Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-48905 Lack of input filtering leads to an XSS vector in the HTML filter code. Joomla\! 5.4.6 / 6.1.0+ Fix from $1,6002026-05-26 CRITICAL 9.8 CVE-2026-48898 An improper access check allows privilege escalation through the com_users batch task. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-48899 An improper access check allows privilege escalation through the com_users batch task. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-48902 The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 HIGH 7.5 CVE-2026-48896 Insufficient state checks lead to a vector that allows to bypass 2FA checks. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-48897 Insufficient state checks lead to a vector that allows to bypass 2FA checks. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-48901 The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-40383 An improper validation of user-supplied input leads to a local file inclusion vulnerability. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 HIGH 7.5 CVE-2026-40384 An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,9502026-05-26 CRITICAL 9.8 CVE-2026-35223 An improper access check allows unauthorized access to com_config webservice endpoints. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-35221 Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-35222 Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 MEDIUM 6.1 CVE-2026-30895 Lack of output escaping leads to a XSS vector in the readmore links for com_content. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-25900 Lack of output escaping leads to a XSS vector in the feed modules. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-25901 Lack of output escaping leads to a XSS vector in the multilingual associations component. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 MEDIUM 6.1 CVE-2026-30894 Lack of output escaping leads to a XSS vector in the content history component. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,6002026-05-26 HIGH 8.8 CVE-2026-23899 An improper access check allows unauthorized access to webservice endpoints. Joomla\! 5.4.4 / 6.0.4+ Fix from $1,9502026-04-01