Search Results (877 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73327 1 Joomla 1 Joomla! 2026-08-13 7.6 High
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.
CVE-2026-48954 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Improper validation leads to a generic XSS vector in the language override feature.
CVE-2026-48949 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48948 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 8.8 High
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-48953 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48951 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48957 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 8.8 High
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48956 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 5.0 Medium
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48955 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.5 Medium
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48950 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48958 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 8.8 High
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48947 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 4.9 Medium
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48952 1 Joomla 2 Joomla!, Joomla\! 2026-07-10 6.1 Medium
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-35222 1 Joomla 2 Joomla!, Joomla\! 2026-06-02 9.8 Critical
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-30894 1 Joomla 2 Joomla!, Joomla\! 2026-06-02 6.1 Medium
Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-35220 1 Joomla 2 Joomla!, Joomla\! 2026-05-29 4.3 Medium
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-48896 1 Joomla 2 Joomla!, Joomla\! 2026-05-29 7.5 High
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48903 1 Joomla 2 Joomla! Framework Filter Package, Joomla\! 2026-05-29 6.1 Medium
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48902 1 Joomla 2 Joomla!, Joomla\! 2026-05-28 9.8 Critical
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVE-2026-48897 1 Joomla 2 Joomla!, Joomla\! 2026-05-28 7.5 High
Insufficient state checks lead to a vector that allows to bypass 2FA checks.