Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.39% | — | Joomlafry TF ContentAI | 5/10/2026 | 6/10/2026 | Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of… | |
| Pendiente de análisis | Media (6.9) | 0.26% | — | Joomlafry TF ContentAI | 5/10/2026 | 6/10/2026 | Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the… | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | — | Ordasoft Joomla CCKAI | 5/10/2026 | 6/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector. | |
| Analizada | Crítica (10) | 0.79% | 💥 PoC | Ordasoft Joomla CCK | 30/9/2026 | 1/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s… | |
| Analizada | Alta (7.1) | 0.27% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector. | |
| Analizada | Alta (7.1) | 0.27% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS… | |
| Analizada | Alta (8.2) | 0.34% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability. | |
| Analizada | Alta (7) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items. | |
| Analizada | Media (5.9) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector. | |
| Analizada | Media (5.9) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector. | |
| Analizada | Media (5.1) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents. | |
| Analizada | Alta (8.9) | 0.21% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors. | |
| Analizada | Media (6.9) | 0.27% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | |
| Analizada | Media (6.9) | 0.27% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories. | |
| Analizada | Media (5.1) | 0.24% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents. | |
| Analizada | Alta (7) | 0.33% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions. | |
| Analizada | Media (5.9) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts. | |
| Analizada | Alta (7) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints. | |
| Analizada | Media (6.9) | 0.25% | 💥 PoC | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration. | |
| Analizada | Media (5.9) | 0.26% | — | Joomla! | 29/9/2026 | 6/10/2026 | Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper. | |
| En análisis | Crítica (9.3) | 0.38% | 💥 PoC | Joomlaboat Youtube GalleryAI | 26/9/2026 | 29/9/2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries. | |
| En análisis | Alta (7.2) | 0.26% | — | Joomla Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core Joomla mail configuration (fromname, mailfrom) in configuration.php without… | |
| En análisis | Alta (8.6) | 0.28% | — | Joomshaper Easy StoreAIJoomlaAI | 23/9/2026 | 25/9/2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) took input IDs and directly concatenated them into raw SQL IN (...) clauses in… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a… |