Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

866 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.54%—J2storeAIJoomlaAI21/8/202626/8/2026
Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication…
AplazadaMedia (6.3)0.41%—J2storeAIJoomlaAI21/8/202626/8/2026
Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.
AplazadaMedia (6.9)0.45%—Tassos Convert FormsAIJoomlaAI20/8/202626/8/2026
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
AplazadaMedia (5.1)0.44%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
AplazadaAlta (7.5)0.42%—Cmsjunkie J-businessdirectoryAIJoomlaAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
AplazadaCrítica (10)0.43%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also…
AnalizadaMedia (5.1)0.29%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
AnalizadaMedia (5.1)0.27%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
AnalizadaMedia (5.1)0.26%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
AnalizadaMedia (6.9)0.34%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
AnalizadaMedia (4.8)0.24%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
AnalizadaAlta (8.9)0.65%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
AnalizadaMedia (5.1)0.29%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
AnalizadaAlta (8.2)0.46%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
AnalizadaMedia (5.1)0.26%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
AnalizadaAlta (8.5)0.34%—Joomla!18/8/20263/9/2026
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
AplazadaCrítica (9.3)0.39%—Joomlack Page Builder CKAI17/8/202626/8/2026
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
AplazadaCrítica (10)0.44%—JoomlaAIRegularlabs SourcererAI17/8/202626/8/2026
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.
RechazadaSin puntuar——JoomlaAI12/8/202617/8/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives.
AplazadaAlta (8.3)0.49%—JoomlaAIOllyo SP Page BuilderAI27/7/202627/7/2026
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.
AplazadaAlta (7.5)0.50%—Regularlabs Rereplacer PROAIJoomlaAI23/7/202628/7/2026
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
AplazadaMedia (6.2)0.19%—Regularlabs Joomla PROAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
AplazadaCrítica (9.8)0.52%—Regularlabs Cache Cleaner PROAIJoomlaAI23/7/202627/7/2026
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
AplazadaCrítica (9.8)0.48%—JoomlaAIRegularlabs Cache Cleaner PROAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
AplazadaMedia (6.5)0.33%—Regularlabs Cache Cleaner PROAIJoomlaAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.
Orbitaley — Vulnerabilidades