Where
-Infinity
0

Joomla Joomla\!Joomla! Core - [20260706] - XSS in com_installer

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints

Risk 66
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints

Risk 79
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260704] - XSS in com_templates

Risk 38
Severity
5.9
First published (updated )

Joomla! Joomla! CoreJoomla! Core - [20260709] - Incorrect Access Control in com_workflow

Risk 38
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260710] - Incorrect Access Control in com_modules

Risk 66
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints

Risk 79
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260705] - XSS in various modalreturn layouts

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260707] - XSS in the generic image output layout

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download

Risk 79
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260703] - XSS in MFA method management

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260708] - XSS through language overrides

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder

Risk 86
Severity
6.9
First published (updated )

Joomla Joomla\!Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.

Risk 49
Severity
6.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260511] - MFA Authentication Bypass

Risk 43
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla! CoreJoomla! Core - [20260505] - CSRF in user activation endpoint

Risk 21
Severity
4.6
First published (updated )

Joomla Joomla\!Joomla! Core - [20260509] - LFI in HTMLView layout parameter

Risk 86
Severity
7.5
First published (updated )

Joomla Joomla\!Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags

Risk 86
Severity
6.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint

Risk 43
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.

Risk 49
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260512] - MFA Authentication Bypass

Risk 43
Severity
8.2
First published (updated )

Joomla Joomla\!Joomla! Core - [20260502] - XSS in com_associations

Risk 49
Severity
6.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins

Risk 86
Severity
5.3
First published (updated )

Joomla Joomla\!Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler

Risk 66
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints

Risk 86
Severity
8.6
First published (updated )

Joomla Joomla\!Joomla! Core - [20260501] - XSS in feed modules

Risk 49
Severity
6.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints

Risk 86
Severity
8.2
First published (updated )

Joomla Joomla\!Joomla! Core - [20260504] - XSS in readmore links

Risk 49
Severity
6.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260513] - Privilege escalation through com_users batch task

Risk 86
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203