« Volver al listado

Joomla

Joomla!: vulnerabilidades y CVE

Joomla! tiene 324 vulnerabilidades publicadas, 50 de ellas en los últimos 12 meses. 30 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE324
Últimos 12 meses50
Críticas30
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2016-10033Crítica (9.8)100%⚠ Explotación activa30 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double…
CVE-2023-23752Media (5.3)100%⚠ Explotación activa16 feb 2023
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73372Media (5.1)0.29%—18 ago 2026
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into…
CVE-2026-73336Media (5.1)0.27%—18 ago 2026
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
CVE-2026-72531Media (5.1)0.26%—18 ago 2026
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
CVE-2026-71573Media (6.9)0.34%—18 ago 2026
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
CVE-2026-71572Media (4.8)0.24%—18 ago 2026
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file…
CVE-2026-73373Alta (8.9)0.65%—18 ago 2026
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead…
CVE-2026-73371Media (5.1)0.29%—18 ago 2026
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
CVE-2026-73337Alta (8.2)0.46%—18 ago 2026
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-72532Media (5.1)0.26%—18 ago 2026
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
CVE-2026-71574Alta (8.5)0.34%—18 ago 2026
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice…
CVE-2026-48958Media (6.4)0.46%—7 jul 2026
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48957Media (6.4)0.42%—7 jul 2026
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48956Media (6.4)0.27%—7 jul 2026
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48955Media (6.4)0.34%—7 jul 2026
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48954Media (5.9)0.24%—7 jul 2026
Improper validation leads to a generic XSS vector in the language override feature.
CVE-2026-48953Media (5.9)0.24%—7 jul 2026
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48952Media (5.9)0.24%—7 jul 2026
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48951Media (5.9)0.24%—7 jul 2026
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48950Media (5.9)0.24%—7 jul 2026
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48949Media (5.9)0.24%—7 jul 2026
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48948Media (6.4)0.42%—7 jul 2026
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-48947Media (6.4)0.33%—7 jul 2026
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48905Media (6.9)0.24%—26 may 2026
Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48904Alta (8.2)0.53%—26 may 2026
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48903Media (6.9)0.24%—26 may 2026
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48902Crítica (9.8)0.33%—26 may 2026
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVE-2026-48901Alta (7.5)0.42%—26 may 2026
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48900Media (6.4)0.26%—26 may 2026
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-48899Media (5.3)0.42%—26 may 2026
An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898Alta (8.2)0.48%—26 may 2026
An improper access check allows privilege escalation through the com_users batch task.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application13
  2. T1005 Data from Local System6
  3. T1210 Exploitation of Remote Services6
  4. T1078 Valid Accounts4
  5. T1068 Exploitation for Privilege Escalation2
  6. T1565.002 Transmitted Data Manipulation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Joomla