Joomla

Joomla!

172 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 29.09.2026 17:17:15
  • Zuletzt bearbeitet 06.10.2026 16:46:16

Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circu...

  • EPSS 0.21%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:35:33

Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.

  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:35:41

Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.

  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:35:49

Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.

  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:35:56

Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.

  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:36:01

Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.

  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:40:14

Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.

  • EPSS 0.27%
  • Veröffentlicht 29.09.2026 17:17:14
  • Zuletzt bearbeitet 06.10.2026 16:41:22

Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex...

  • EPSS 0.25%
  • Veröffentlicht 29.09.2026 17:17:13
  • Zuletzt bearbeitet 06.10.2026 16:48:24

Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on ...

  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 17:17:13
  • Zuletzt bearbeitet 06.10.2026 16:33:08

Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints.