Where
-Infinity
0

Joomla Page Builder CKJoomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2

Risk 81
Severity
9.4
First published (updated )

Joomla ChronoFormsJoomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52

Risk 78
Severity
8.7
First published (updated )

Joomla 4AnalyticsJoomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2

Risk 78
Severity
8.7
First published (updated )

Joomla DP CalendarJoomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2

Risk 47
Severity
8.7
First published (updated )

Joomla Joomla\!Joomla! Core - [20260706] - XSS in com_installer

Risk 38
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints

Risk 66
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints

Risk 79
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260704] - XSS in com_templates

Risk 38
Severity
5.9
First published (updated )

Joomla! Joomla! CoreJoomla! Core - [20260709] - Incorrect Access Control in com_workflow

Risk 38
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260710] - Incorrect Access Control in com_modules

Risk 66
Severity
6.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints

Risk 79
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260705] - XSS in various modalreturn layouts

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260707] - XSS in the generic image output layout

Risk 38
Severity
5.9
First published (updated )

Joomla Joomla\!Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download

Risk 79
Severity
6.4
First published (updated )

Joomla Joomla\!Joomla! Core - [20260703] - XSS in MFA method management

Risk 38
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla Joomla\!Joomla! Core - [20260708] - XSS through language overrides

Risk 38
Severity
5.9
First published (updated )

Joomla Helix3 template pluginJoomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler

Risk 43
Severity
7.5
First published (updated )

Joomla K2 extensionJoomla Extension - getk2.org - Unauthenticated folder delete in K2 extension for Joomla < 2.26

Risk 40
Severity
6.5
First published (updated )

Joomla getk2.com K2 extensionJoomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26

Risk 46
Severity
6.3
First published (updated )

Joomla K2 extension (getk2.com)Joomla Extension - getk2.org - Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla K2 system user plugin (plg_user_k2)Joomla Extension - getk2.org - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26

Risk 40
Severity
6.5
First published (updated )

Joomla com_bookingJoomla com_booking 2.4.9 Information Disclosure via Account Enumeration

Risk 47
Severity
8.7
First published (updated )

Joomla Easy ShopJoomla! Component Easy Shop 1.2.3 Local File Inclusion

Risk 38
Severity
6.9
First published (updated )

Joomla vReviewJoomla vReview 1.9.11 SQL Injection via editReview

Risk 57
Severity
8.8
First published (updated )

Joomla vRestaurantJoomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout

Risk 57
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Joomla VMapJoomla! Component VMap 1.9.6 SQL Injection via loadmarker

Risk 57
Severity
8.8
First published (updated )

Joomla J-MultipleHotelReservationJoomla J-MultipleHotelReservation 6.0.7 SQL Injection

Risk 57
Severity
8.8
First published (updated )

Joomla J-CruisePortalJoomla J-CruisePortal 6.0.4 SQL Injection via cruises

Risk 49
Severity
7.1
First published (updated )

Joomla JHotelReservationJoomla JHotelReservation 6.0.7 SQL Injection via search-hotels

Risk 57
Severity
8.8
First published (updated )

Joomla Extra Search (com_extrasearch)Joomla! Component Extra Search 2.2.8 SQL Injection

Risk 57
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203