CVE-2026-48952
- EPSS 0.27%
- Veröffentlicht 07.07.2026 17:33:39
- Zuletzt bearbeitet 09.07.2026 13:43:43
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48947
- EPSS 0.25%
- Veröffentlicht 07.07.2026 17:32:45
- Zuletzt bearbeitet 09.07.2026 14:26:48
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48951
- EPSS 0.27%
- Veröffentlicht 07.07.2026 17:30:24
- Zuletzt bearbeitet 09.07.2026 13:44:41
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48953
- EPSS 0.27%
- Veröffentlicht 07.07.2026 17:30:00
- Zuletzt bearbeitet 09.07.2026 13:32:08
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48949
- EPSS 0.27%
- Veröffentlicht 07.07.2026 17:29:33
- Zuletzt bearbeitet 09.07.2026 13:52:59
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-35220
- EPSS 0.11%
- Veröffentlicht 26.05.2026 16:45:19
- Zuletzt bearbeitet 20.07.2026 20:10:00
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-21631
- EPSS 0.22%
- Veröffentlicht 01.04.2026 09:03:17
- Zuletzt bearbeitet 09.04.2026 19:55:58
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2025-63082
- EPSS 0.18%
- Veröffentlicht 06.01.2026 16:01:38
- Zuletzt bearbeitet 30.01.2026 18:41:18
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
CVE-2025-63083
- EPSS 0.18%
- Veröffentlicht 06.01.2026 16:01:15
- Zuletzt bearbeitet 30.01.2026 18:41:36
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVE-2024-27187
- EPSS 0.35%
- Veröffentlicht 20.08.2024 16:15:10
- Zuletzt bearbeitet 04.06.2025 20:58:17
Improper Access Controls allows backend users to overwrite their username when disallowed.