Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-48957
An improper access check allows unauthorized users to access com_privacy datasets.
Joomla\!
5.4.7 / 6.1.2+
HIGH 8.8
CVE-2026-48958
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.5
CVE-2026-48955
An improper access check allows unauthorized users to access workflow stage and transition information.
Joomla\!
6.1.2+
MEDIUM 6.1
CVE-2026-48954
Improper validation leads to a generic XSS vector in the language override feature.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 5.0
CVE-2026-48956
An improper access check allows users to display a list of modules in the frontend.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48949
Lack of validation leads to an XSS vulnerability in the MFA management views.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48950
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48951
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48952
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Joomla\!
5.4.7 / 6.1.2+
MEDIUM 6.1
CVE-2026-48953
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Joomla\!
5.4.7 / 6.1.2+
HIGH 8.8
CVE-2026-48948
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Joomla\!
5.4.7 / 6.1.2+
CRITICAL 9.8
CVE-2026-48904
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-48903
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-48905
Lack of input filtering leads to an XSS vector in the HTML filter code.
Joomla\!
5.4.6 / 6.1.0+
CRITICAL 9.8
CVE-2026-48898
An improper access check allows privilege escalation through the com_users batch task.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-48899
An improper access check allows privilege escalation through the com_users batch task.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-48902
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.5
CVE-2026-48896
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.5
CVE-2026-48897
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.5
CVE-2026-48901
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-40383
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.5
CVE-2026-40384
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-35223
An improper access check allows unauthorized access to com_config webservice endpoints.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-35221
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
Joomla\!
5.4.6 / 6.1.1+
CRITICAL 9.8
CVE-2026-35222
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-30895
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-25900
Lack of output escaping leads to a XSS vector in the feed modules.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-25901
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Joomla\!
5.4.6 / 6.1.1+
MEDIUM 6.1
CVE-2026-30894
Lack of output escaping leads to a XSS vector in the content history component.
Joomla\!
5.4.6 / 6.1.1+
HIGH 8.8
CVE-2026-23899
An improper access check allows unauthorized access to webservice endpoints.
Joomla\!
5.4.4 / 6.0.4+