Joomla
Joomla!: vulnerabilidades y CVE
Joomla! tiene 324 vulnerabilidades publicadas, 50 de ellas en los últimos 12 meses. 30 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE324
Últimos 12 meses50
Críticas30
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-10033 | Crítica (9.8) | 100% | ⚠ Explotación activa | 30 dic 2016 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double… |
| CVE-2023-23752 | Media (5.3) | 100% | ⚠ Explotación activa | 16 feb 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73372 | Media (5.1) | 0.29% | — | 18 ago 2026 | Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into… |
| CVE-2026-73336 | Media (5.1) | 0.27% | — | 18 ago 2026 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. |
| CVE-2026-72531 | Media (5.1) | 0.26% | — | 18 ago 2026 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. |
| CVE-2026-71573 | Media (6.9) | 0.34% | — | 18 ago 2026 | Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. |
| CVE-2026-71572 | Media (4.8) | 0.24% | — | 18 ago 2026 | Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file… |
| CVE-2026-73373 | Alta (8.9) | 0.65% | — | 18 ago 2026 | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead… |
| CVE-2026-73371 | Media (5.1) | 0.29% | — | 18 ago 2026 | Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. |
| CVE-2026-73337 | Alta (8.2) | 0.46% | — | 18 ago 2026 | Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-72532 | Media (5.1) | 0.26% | — | 18 ago 2026 | Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. |
| CVE-2026-71574 | Alta (8.5) | 0.34% | — | 18 ago 2026 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice… |
| CVE-2026-48958 | Media (6.4) | 0.46% | — | 7 jul 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. |
| CVE-2026-48957 | Media (6.4) | 0.42% | — | 7 jul 2026 | An improper access check allows unauthorized users to access com_privacy datasets. |
| CVE-2026-48956 | Media (6.4) | 0.27% | — | 7 jul 2026 | An improper access check allows users to display a list of modules in the frontend. |
| CVE-2026-48955 | Media (6.4) | 0.34% | — | 7 jul 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. |
| CVE-2026-48954 | Media (5.9) | 0.24% | — | 7 jul 2026 | Improper validation leads to a generic XSS vector in the language override feature. |
| CVE-2026-48953 | Media (5.9) | 0.24% | — | 7 jul 2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. |
| CVE-2026-48952 | Media (5.9) | 0.24% | — | 7 jul 2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. |
| CVE-2026-48951 | Media (5.9) | 0.24% | — | 7 jul 2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. |
| CVE-2026-48950 | Media (5.9) | 0.24% | — | 7 jul 2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. |
| CVE-2026-48949 | Media (5.9) | 0.24% | — | 7 jul 2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. |
| CVE-2026-48948 | Media (6.4) | 0.42% | — | 7 jul 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
| CVE-2026-48947 | Media (6.4) | 0.33% | — | 7 jul 2026 | An improper access check allows privileged users to overwrite media files without editing permissions. |
| CVE-2026-48905 | Media (6.9) | 0.24% | — | 26 may 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. |
| CVE-2026-48904 | Alta (8.2) | 0.53% | — | 26 may 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. |
| CVE-2026-48903 | Media (6.9) | 0.24% | — | 26 may 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. |
| CVE-2026-48902 | Crítica (9.8) | 0.33% | — | 26 may 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. |
| CVE-2026-48901 | Alta (7.5) | 0.42% | — | 26 may 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. |
| CVE-2026-48900 | Media (6.4) | 0.26% | — | 26 may 2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. |
| CVE-2026-48899 | Media (5.3) | 0.42% | — | 26 may 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48898 | Alta (8.2) | 0.48% | — | 26 may 2026 | An improper access check allows privilege escalation through the com_users batch task. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.