Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla\! HIGH 8.8
CVE-2026-48957

An improper access check allows unauthorized users to access com_privacy datasets.

Fix: 5.4.7 / 6.1.2+
Fix from $1,950 2026-07-07
Joomla\! HIGH 8.8
CVE-2026-48958

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

Fix: 5.4.7 / 6.1.2+
Fix from $1,950 2026-07-07
Joomla\! MEDIUM 6.5
CVE-2026-48955

An improper access check allows unauthorized users to access workflow stage and transition information.

Fix: 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48954

Improper validation leads to a generic XSS vector in the language override feature.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 5.0
CVE-2026-48956

An improper access check allows users to display a list of modules in the frontend.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48949

Lack of validation leads to an XSS vulnerability in the MFA management views.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48950

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48951

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48952

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! MEDIUM 6.1
CVE-2026-48953

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

Fix: 5.4.7 / 6.1.2+
Fix from $1,600 2026-07-07
Joomla\! HIGH 8.8
CVE-2026-48948

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

Fix: 5.4.7 / 6.1.2+
Fix from $1,950 2026-07-07
Joomla\! CRITICAL 9.8
CVE-2026-48904

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-48903

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-48905

Lack of input filtering leads to an XSS vector in the HTML filter code.

Fix: 5.4.6 / 6.1.0+
Fix from $1,600 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48898

An improper access check allows privilege escalation through the com_users batch task.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48899

An improper access check allows privilege escalation through the com_users batch task.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48902

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-48896

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-48897

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-48901

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-40383

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-40384

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35223

An improper access check allows unauthorized access to com_config webservice endpoints.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35221

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35222

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-30895

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-25900

Lack of output escaping leads to a XSS vector in the feed modules.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-25901

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! MEDIUM 6.1
CVE-2026-30894

Lack of output escaping leads to a XSS vector in the content history component.

Fix: 5.4.6 / 6.1.1+
Fix from $1,600 2026-05-26
Joomla\! HIGH 8.8
CVE-2026-23899

An improper access check allows unauthorized access to webservice endpoints.

Fix: 5.4.4 / 6.0.4+
Fix from $1,950 2026-04-01