CVE-2026-48949
- EPSS 0.27%
- Veröffentlicht 07.07.2026 17:29:33
- Zuletzt bearbeitet 09.07.2026 13:52:59
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-35220
- EPSS 0.11%
- Veröffentlicht 26.05.2026 16:45:19
- Zuletzt bearbeitet 20.07.2026 20:10:00
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-21631
- EPSS 0.22%
- Veröffentlicht 01.04.2026 09:03:17
- Zuletzt bearbeitet 09.04.2026 19:55:58
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2024-27187
- EPSS 0.35%
- Veröffentlicht 20.08.2024 16:15:10
- Zuletzt bearbeitet 04.06.2025 20:58:17
Improper Access Controls allows backend users to overwrite their username when disallowed.
CVE-2024-21731
- EPSS 0.44%
- Veröffentlicht 09.07.2024 17:15:14
- Zuletzt bearbeitet 13.03.2025 15:15:41
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
CVE-2024-26278
- EPSS 0.45%
- Veröffentlicht 09.07.2024 17:15:14
- Zuletzt bearbeitet 13.03.2025 16:15:18
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
CVE-2023-40626
- EPSS 0.81%
- Veröffentlicht 29.11.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 08:19:51
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
CVE-2023-23754
- EPSS 0.41%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 09.01.2025 22:15:25
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
CVE-2023-23755
- EPSS 0.56%
- Veröffentlicht 30.05.2023 17:15:09
- Zuletzt bearbeitet 09.01.2025 22:15:26
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
CVE-2022-27914
- EPSS 0.47%
- Veröffentlicht 08.11.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:56:27
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.