Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

340 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.51%—Joomla!26/5/202624/7/2026
An improper access check allows unauthorized access to com_config webservice endpoints.
AnalizadaMedia (6.9)0.45%—Joomla!26/5/202624/7/2026
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
AnalizadaMedia (6.9)0.45%—Joomla!26/5/202624/7/2026
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
AnalizadaMedia (4.6)0.14%—Joomla!26/5/202620/7/2026
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
AnalizadaMedia (6.9)0.24%—Joomla!26/5/202624/7/2026
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
AnalizadaMedia (6.9)0.24%—Joomla!26/5/202624/7/2026
Lack of output escaping leads to a XSS vector in the content history component.
AnalizadaMedia (6.9)0.24%—Joomla!26/5/202624/7/2026
Lack of output escaping leads to a XSS vector in the multilingual associations component.
AnalizadaMedia (6.9)0.24%—Joomla!26/5/202620/7/2026
Lack of output escaping leads to a XSS vector in the feed modules.
AnalizadaAlta (8.6)0.40%—Joomla!1/4/202617/6/2026
An improper access check allows unauthorized access to webservice endpoints.
AnalizadaAlta (8.6)0.45%—Joomla!1/4/202617/6/2026
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
AnalizadaMedia (5.9)0.19%—Joomla!1/4/202617/6/2026
Lack of output escaping for article titles leads to XSS vectors in various locations.
AnalizadaMedia (5.9)0.22%—Joomla!1/4/202617/6/2026
Lack of output escaping leads to a XSS vector in the multilingual associations component.
AnalizadaMedia (6.9)0.34%—Joomla!1/4/202617/6/2026
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
AnalizadaMedia (6.3)0.25%—Joomla!1/4/202617/6/2026
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
AnalizadaMedia (5.9)0.36%—Joomla!6/1/20267/10/2026
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
AnalizadaMedia (5.9)0.36%—Joomla!6/1/20267/10/2026
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
AnalizadaAlta (7.5)0.40%💥 PoCJoomla!8/4/202517/6/2026
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
AnalizadaCrítica (9.8)0.47%—Joomla!8/4/202517/6/2026
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited…
AnalizadaAlta (7.5)0.38%—Joomla!7/1/202517/6/2026
Improper Access Controls allows access to protected views.
AnalizadaAlta (7.5)0.42%—Joomla!7/1/202517/6/2026
Lack of output escaping in the id attribute of menu lists.
AnalizadaMedia (6.1)0.25%—Joomla!7/1/202517/6/2026
Various module chromes didn't properly process inputs, leading to XSS vectors.
AnalizadaMedia (6.1)0.27%—Joomla!20/8/202417/6/2026
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
AnalizadaAlta (7.5)0.35%—Joomla!20/8/202417/6/2026
Improper Access Controls allows backend users to overwrite their username when disallowed.
AnalizadaMedia (6.1)0.27%—Joomla!20/8/202417/6/2026
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
AnalizadaCrítica (9.1)0.44%—Joomla!20/8/202417/6/2026
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
Orbitaley — Vulnerabilidades