Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

340 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.34%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
AnalizadaMedia (6.4)0.46%—Joomla!7/7/20269/7/2026
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
AnalizadaMedia (6.4)0.42%—Joomla!7/7/20269/7/2026
An improper access check allows unauthorized users to access com_privacy datasets.
AnalizadaMedia (6.4)0.27%—Joomla!7/7/20269/7/2026
An improper access check allows users to display a list of modules in the frontend.
AnalizadaMedia (6.4)0.34%—Joomla!7/7/20269/7/2026
An improper access check allows unauthorized users to access workflow stage and transition information.
En análisisMedia (5.9)0.24%—Joomla!7/7/20269/7/2026
Improper validation leads to a generic XSS vector in the language override feature.
AnalizadaMedia (5.9)0.24%—Joomla!7/7/20269/7/2026
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
AnalizadaMedia (5.9)0.24%—Joomla!7/7/20269/7/2026
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
AnalizadaMedia (5.9)0.24%—Joomla!7/7/20269/7/2026
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
AnalizadaMedia (5.9)0.24%—Joomla!7/7/20269/7/2026
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
AnalizadaMedia (5.9)0.24%—Joomla!7/7/20269/7/2026
Lack of validation leads to an XSS vulnerability in the MFA management views.
AnalizadaMedia (6.4)0.42%—Joomla!7/7/20269/7/2026
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
AnalizadaMedia (6.4)0.33%—Joomla!7/7/20269/7/2026
An improper access check allows privileged users to overwrite media files without editing permissions.
AnalizadaMedia (6.9)0.24%—Joomla!26/5/202620/7/2026
Lack of input filtering leads to an XSS vector in the HTML filter code.
AnalizadaAlta (8.2)0.53%—Joomla!26/5/202624/7/2026
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
AnalizadaMedia (6.9)0.24%—Joomla!26/5/202624/7/2026
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
ModificadaCrítica (9.8)0.33%—Joomla!26/5/202624/7/2026
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
AnalizadaAlta (7.5)0.42%—Joomla!26/5/202624/7/2026
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
AnalizadaMedia (6.4)0.26%—Joomla!26/5/202624/7/2026
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
AnalizadaMedia (5.3)0.42%—Joomla!26/5/202624/7/2026
An improper access check allows privilege escalation through the com_users batch task.
AnalizadaAlta (8.2)0.48%—Joomla!26/5/202624/7/2026
An improper access check allows privilege escalation through the com_users batch task.
AnalizadaAlta (8.2)0.36%—Joomla!26/5/202624/7/2026
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
AnalizadaAlta (8.2)0.36%—Joomla!26/5/202624/7/2026
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
AnalizadaMedia (5.9)0.49%—Joomla!26/5/202624/7/2026
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
AnalizadaAlta (7.5)0.56%—Joomla!26/5/202624/7/2026
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Orbitaley — Vulnerabilidades