Joomla

Joomla!

172 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 18.08.2026 16:05:56
  • Zuletzt bearbeitet 03.09.2026 15:06:03

Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confus...

  • EPSS 0.34%
  • Veröffentlicht 18.08.2026 16:04:51
  • Zuletzt bearbeitet 03.09.2026 14:59:39

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • EPSS 0.29%
  • Veröffentlicht 18.08.2026 16:04:11
  • Zuletzt bearbeitet 03.09.2026 15:00:36

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

  • EPSS 0.32%
  • Veröffentlicht 18.08.2026 16:03:44
  • Zuletzt bearbeitet 03.09.2026 15:07:27

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.

  • EPSS 0.31%
  • Veröffentlicht 18.08.2026 16:03:43
  • Zuletzt bearbeitet 03.09.2026 15:06:54

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

  • EPSS 0.26%
  • Veröffentlicht 18.08.2026 16:02:54
  • Zuletzt bearbeitet 03.09.2026 15:07:57

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation...

  • EPSS 0.27%
  • Veröffentlicht 07.07.2026 17:33:39
  • Zuletzt bearbeitet 09.07.2026 13:43:43

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

  • EPSS 0.25%
  • Veröffentlicht 07.07.2026 17:32:45
  • Zuletzt bearbeitet 09.07.2026 14:26:48

An improper access check allows privileged users to overwrite media files without editing permissions.

  • EPSS 0.27%
  • Veröffentlicht 07.07.2026 17:30:24
  • Zuletzt bearbeitet 09.07.2026 13:44:41

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

  • EPSS 0.27%
  • Veröffentlicht 07.07.2026 17:30:00
  • Zuletzt bearbeitet 09.07.2026 13:32:08

Lack of escaping leads to an XSS vulnerability in the generic image output layout.