Export limit exceeded: 387133 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387133 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (653 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-71574 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 6.5 Medium |
| Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI. | ||||
| CVE-2026-72532 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 5.4 Medium |
| Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. | ||||
| CVE-2026-73373 | 1 Joomla | 3 Joomla!, Joomla! Framework Filter Package, Joomla\! | 2026-09-03 | 9.8 Critical |
| Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. | ||||
| CVE-2026-71572 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 5.4 Medium |
| Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. | ||||
| CVE-2026-71573 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 8.3 High |
| Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. | ||||
| CVE-2026-72531 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 5.4 Medium |
| Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | ||||
| CVE-2026-73336 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 6.4 Medium |
| Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||||
| CVE-2026-73372 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 4.3 Medium |
| Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. | ||||
| CVE-2026-73371 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 4.3 Medium |
| Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. | ||||
| CVE-2026-73337 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-09-03 | 7.5 High |
| Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. | ||||
| CVE-2026-48954 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 6.1 Medium |
| Improper validation leads to a generic XSS vector in the language override feature. | ||||
| CVE-2026-48949 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 6.1 Medium |
| Lack of validation leads to an XSS vulnerability in the MFA management views. | ||||
| CVE-2026-48948 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 8.8 High |
| An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | ||||
| CVE-2026-48953 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 6.1 Medium |
| Lack of escaping leads to an XSS vulnerability in the generic image output layout. | ||||
| CVE-2026-48951 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 6.1 Medium |
| Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | ||||
| CVE-2026-48957 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 8.8 High |
| An improper access check allows unauthorized users to access com_privacy datasets. | ||||
| CVE-2026-48956 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 5.0 Medium |
| An improper access check allows users to display a list of modules in the frontend. | ||||
| CVE-2026-48955 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 6.5 Medium |
| An improper access check allows unauthorized users to access workflow stage and transition information. | ||||
| CVE-2026-48950 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 6.1 Medium |
| Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | ||||
| CVE-2026-48958 | 1 Joomla | 2 Joomla!, Joomla\! | 2026-07-10 | 8.8 High |
| An improper access check allows unauthorized users to create custom fields via webservices endpoints. | ||||