Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.54% | — | J2storeAIJoomlaAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication… | |
| Aplazada | Media (6.3) | 0.41% | — | J2storeAIJoomlaAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked. | |
| Aplazada | Media (6.9) | 0.45% | — | Tassos Convert FormsAIJoomlaAI | 20/8/2026 | 26/8/2026 | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | |
| Aplazada | Media (5.1) | 0.44% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute. | |
| Aplazada | Alta (7.5) | 0.42% | — | Cmsjunkie J-businessdirectoryAIJoomlaAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address. | |
| Aplazada | Crítica (10) | 0.43% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also… | |
| Analizada | Media (5.1) | 0.29% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. | |
| Analizada | Media (5.1) | 0.27% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | |
| Analizada | Media (5.1) | 0.26% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | |
| Analizada | Media (6.9) | 0.34% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. | |
| Analizada | Media (4.8) | 0.24% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. | |
| Analizada | Alta (8.9) | 0.65% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. | |
| Analizada | Media (5.1) | 0.29% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. | |
| Analizada | Alta (8.2) | 0.46% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| Analizada | Media (5.1) | 0.26% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. | |
| Analizada | Alta (8.5) | 0.34% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joomlack Page Builder CKAI | 17/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend. | |
| Aplazada | Crítica (10) | 0.44% | — | JoomlaAIRegularlabs SourcererAI | 17/8/2026 | 26/8/2026 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated. | |
| Rechazada | Sin puntuar | — | — | JoomlaAI | 12/8/2026 | 17/8/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives. | |
| Aplazada | Alta (8.3) | 0.49% | — | JoomlaAIOllyo SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. | |
| Aplazada | Alta (7.5) | 0.50% | — | Regularlabs Rereplacer PROAIJoomlaAI | 23/7/2026 | 28/7/2026 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. | |
| Aplazada | Media (6.2) | 0.19% | — | Regularlabs Joomla PROAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Regularlabs Cache Cleaner PROAIJoomlaAI | 23/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. | |
| Aplazada | Crítica (9.8) | 0.48% | — | JoomlaAIRegularlabs Cache Cleaner PROAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | |
| Aplazada | Media (6.5) | 0.33% | — | Regularlabs Cache Cleaner PROAIJoomlaAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory. |