CVE-2026-90914
- EPSS 0.26%
- Veröffentlicht 29.09.2026 17:17:13
- Zuletzt bearbeitet 06.10.2026 16:33:33
Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.
CVE-2026-90915
- EPSS 0.33%
- Veröffentlicht 29.09.2026 17:17:13
- Zuletzt bearbeitet 06.10.2026 16:33:43
Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in ar...
CVE-2026-90916
- EPSS 0.24%
- Veröffentlicht 29.09.2026 17:17:13
- Zuletzt bearbeitet 06.10.2026 16:34:43
Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents.
CVE-2026-90917
- EPSS 0.27%
- Veröffentlicht 29.09.2026 17:17:13
- Zuletzt bearbeitet 06.10.2026 16:35:20
Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.
CVE-2026-90918
- EPSS 0.27%
- Veröffentlicht 29.09.2026 17:17:13
- Zuletzt bearbeitet 06.10.2026 16:35:27
Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVE-2026-90906
- EPSS 0.26%
- Veröffentlicht 29.09.2026 17:17:12
- Zuletzt bearbeitet 06.10.2026 16:48:17
Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper.
CVE-2026-71573
- EPSS 0.34%
- Veröffentlicht 18.08.2026 16:09:47
- Zuletzt bearbeitet 03.09.2026 15:04:22
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
CVE-2026-72531
- EPSS 0.32%
- Veröffentlicht 18.08.2026 16:08:48
- Zuletzt bearbeitet 03.09.2026 15:03:14
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
CVE-2026-73336
- EPSS 0.32%
- Veröffentlicht 18.08.2026 16:06:00
- Zuletzt bearbeitet 03.09.2026 15:01:41
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
CVE-2026-73372
- EPSS 0.29%
- Veröffentlicht 18.08.2026 16:05:57
- Zuletzt bearbeitet 03.09.2026 15:01:06
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.