CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-77997 - Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1
CVE-2026-77996 - Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41
CVE-2026-77995 - Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, O
CVE-2026-77994 - Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla
CVE-2026-77993 - Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Pag
CVE-2026-77992 - Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2
CVE-2026-77027 - Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of use
CVE-2026-76609 - Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - Th
CVE-2026-76608 - Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fab
CVE-2026-76607 - Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
CVE-2026-76606 - Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
CVE-2026-76605 - Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
CVE-2026-76604 - Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabr
CVE-2026-76603 - Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7
CVE-2026-76602 - Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The
CVE-2026-76601 - Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugi
CVE-2026-76600 - Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The De
CVE-2026-76599 - Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in
CVE-2026-76598 - Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders
CVE-2026-76597 - Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email p
CVE-2026-76596 - Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.
CVE-2026-76571 - Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter i
CVE-2026-66917 - Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, pr
CVE-2026-66916 - Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in Jo
CVE-2026-74252 - Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.
CVE-2026-67362 - Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-
CVE-2026-67361 - Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in
CVE-2026-67360 - Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-
CVE-2026-67359 - Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1
CVE-2026-67358 - Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.2
CVE-2026-77028 - Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parame
CVE-2026-76613 - Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.
CVE-2026-76612 - Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1
CVE-2026-76611 - Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery elemen
CVE-2026-75115 - Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.
CVE-2026-77029 - Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
CVE-2026-77026 - Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.
CVE-2026-76610 - Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment co
CVE-2026-76569 - Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1
CVE-2026-76565 - Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Car
CVE-2026-76564 - Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.
CVE-2026-75948 - Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The fronte
CVE-2026-75956 - Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirector
CVE-2026-75955 - Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - co
CVE-2026-75954 - Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - S
CVE-2026-75953 - Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient addre
CVE-2026-75952 - Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Toke
CVE-2026-75951 - Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions)
CVE-2026-75950 - Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory
CVE-2026-75949 - Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessD
CVE-2026-75114 - Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo <
CVE-2026-74804 - Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo
CVE-2026-74803 - Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image
CVE-2026-67364 - Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's
CVE-2026-67363 - Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The
CVE-2026-73372 - Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1
CVE-2026-73336 - Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Impr
CVE-2026-72531 - Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0
CVE-2026-71573 - Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An
CVE-2026-71572 - Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0
CVE-2026-73373 - Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 -
CVE-2026-73371 - Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-
CVE-2026-73337 - Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insuff
CVE-2026-72532 - Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.
CVE-2026-71574 - Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.
CVE-2026-74254 - Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Pag
CVE-2026-74253 - Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in
CVE-2026-74251 - Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.
CVE-2026-71570 - Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A
CVE-2026-67366 - Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 -
CVE-2026-71571 - Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCage
CVE-2026-67365 - Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthe
CVE-2026-73327 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the re
CVE-2026-67287 - Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An
CVE-2026-67286 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in S
CVE-2026-67285 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Bu
CVE-2026-67284 - Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud
CVE-2026-67283 - Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud
CVE-2026-67282 - Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unaut
CVE-2026-66915 - Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attac
CVE-2026-66914 - Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1
CVE-2026-66494 - Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builde
CVE-2026-66493 - Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper
CVE-2026-66492 - Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper
CVE-2026-66491 - Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitati
CVE-2026-65947 - Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65888 - Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogi
CVE-2026-65887 - Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The
CVE-2026-65886 - Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo
CVE-2026-66490 - Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.
CVE-2026-66489 - Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-66488 - Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-65890 - Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi v
CVE-2026-65889 - Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generat
CVE-2026-65946 - Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVE-2026-65944 - Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVE-2026-65943 - Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
CVE-2026-65891 - Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite
CVE-2026-65885 - Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File uplo
CVE-2026-65884 - Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method
CVE-2026-65883 - Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guar
CVE-2026-65882 - Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url param
CVE-2026-65881 - Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account acces
CVE-2026-65880 - Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An
CVE-2026-65879 - Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret
CVE-2026-65878 - Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1-
CVE-2026-65877 - Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improp
CVE-2026-65876 - Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Impr
CVE-2026-65766 - Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Impr
CVE-2026-65765 - Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper
CVE-2026-65764 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper
CVE-2026-65763 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper valid
CVE-2026-65762 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper
CVE-2026-65761 - Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.
CVE-2026-65760 - Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy
CVE-2026-65759 - Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.
CVE-2026-65758 - Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The
CVE-2026-65757 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules An
CVE-2026-65756 - Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configura
CVE-2026-65755 - Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Use
CVE-2026-65754 - Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer
CVE-2026-65713 - Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery
CVE-2026-65712 - Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN ve
CVE-2026-65431 - Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives ha
CVE-2026-65430 - Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credent
CVE-2026-64876 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP ext
CVE-2026-64875 - Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups tr
CVE-2026-64874 - Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN creden
CVE-2026-64873 - Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could a
CVE-2026-64872 - Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge an
CVE-2026-64871 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Clea
CVE-2026-64799 - Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users
CVE-2026-64798 - Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL
CVE-2026-64797 - Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trus
CVE-2026-64796 - Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free di
CVE-2026-64795 - Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs exte
CVE-2026-64794 - Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles An
CVE-2026-64793 - Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and
CVE-2026-64792 - Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Re
CVE-2026-64791 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La
CVE-2026-63685 - Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator r
CVE-2026-63684 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various ad
CVE-2026-63683 - Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions man
CVE-2026-63281 - Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored c
CVE-2026-63280 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La
CVE-2026-63265 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Re
CVE-2026-63264 - Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension
CVE-2026-63048 - Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.1
CVE-2026-63047 - Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Bo
CVE-2026-62415 - Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Jo
CVE-2026-62414 - Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla ext
CVE-2026-61901 - Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop
CVE-2026-61900 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.
CVE-2026-61425 - Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gri
CVE-2026-61424 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.1
CVE-2026-60034 - Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Jooml
CVE-2026-60033 - Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Jooml
CVE-2026-60032 - Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joom
CVE-2026-60031 - Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla
CVE-2026-60030 - Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder
CVE-2026-60029 - Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joom
CVE-2026-60028 - Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joom
CVE-2026-60027 - Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder
CVE-2026-60026 - Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 -
CVE-2026-60025 - Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extens
CVE-2026-60024 - Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Jo
CVE-2026-58149 - Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extens
CVE-2026-58148 - Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 -
CVE-2026-58078 - Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 -
CVE-2026-58077 - Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extens
CVE-2026-57833 - Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extens
CVE-2026-57832 - Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joo
CVE-2026-57831 - Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10
CVE-2026-57830 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.
CVE-2026-57829 - Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Jooml
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware