CVE-2026-71573
- EPSS 0.34%
- Veröffentlicht 18.08.2026 16:09:47
- Zuletzt bearbeitet 18.08.2026 20:17:24
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
CVE-2026-72531
- EPSS 0.32%
- Veröffentlicht 18.08.2026 16:08:48
- Zuletzt bearbeitet 18.08.2026 20:17:25
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
CVE-2026-73336
- EPSS 0.32%
- Veröffentlicht 18.08.2026 16:06:00
- Zuletzt bearbeitet 18.08.2026 20:17:26
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
CVE-2026-73372
- EPSS 0.29%
- Veröffentlicht 18.08.2026 16:05:57
- Zuletzt bearbeitet 18.08.2026 20:17:27
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
CVE-2026-71572
- EPSS 0.32%
- Veröffentlicht 18.08.2026 16:05:56
- Zuletzt bearbeitet 18.08.2026 20:17:24
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confus...
CVE-2026-73337
- EPSS 0.34%
- Veröffentlicht 18.08.2026 16:04:51
- Zuletzt bearbeitet 18.08.2026 20:17:26
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-73371
- EPSS 0.29%
- Veröffentlicht 18.08.2026 16:04:11
- Zuletzt bearbeitet 18.08.2026 20:17:27
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
CVE-2026-72532
- EPSS 0.32%
- Veröffentlicht 18.08.2026 16:03:44
- Zuletzt bearbeitet 18.08.2026 20:17:25
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
CVE-2026-73373
- EPSS 0.31%
- Veröffentlicht 18.08.2026 16:03:43
- Zuletzt bearbeitet 19.08.2026 04:17:38
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
CVE-2026-71574
- EPSS 0.26%
- Veröffentlicht 18.08.2026 16:02:54
- Zuletzt bearbeitet 18.08.2026 20:17:24
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation...