Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▼ 317 vs. last week
Critical / high1,288▼ 233 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
866 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Undergoing Analysis | Medium (6.9) | 0.39% | — | Joomlafry TF ContentAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of… | |
| Undergoing Analysis | Medium (6.9) | 0.26% | — | Joomlafry TF ContentAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the… | |
| Undergoing Analysis | Critical (9.3) | 0.28% | — | Ordasoft Joomla CCKAI | 10/5/2026 | 10/6/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector. | |
| Analyzed | Critical (10) | 0.79% | 💥 PoC | Ordasoft Joomla CCK | 9/30/2026 | 10/1/2026 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s… | |
| Analyzed | High (7.1) | 0.24% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector. | |
| Analyzed | High (7.1) | 0.27% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS… | |
| Analyzed | High (8.2) | 0.27% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability. | |
| Analyzed | High (7) | 0.23% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items. | |
| Analyzed | Medium (5.9) | 0.27% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector. | |
| Analyzed | Medium (5.9) | 0.27% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector. | |
| Analyzed | Medium (5.1) | 0.16% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents. | |
| Analyzed | High (8.9) | 0.24% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors. | |
| Analyzed | Medium (6.9) | 0.20% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | |
| Analyzed | Medium (6.9) | 0.20% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories. | |
| Analyzed | Medium (5.1) | 0.19% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents. | |
| Analyzed | High (7) | 0.34% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions. | |
| Analyzed | Medium (5.9) | 0.22% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts. | |
| Analyzed | High (7) | 0.21% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints. | |
| Analyzed | Medium (6.9) | 0.19% | 💥 PoC | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration. | |
| Analyzed | Medium (5.9) | 0.22% | — | Joomla! | 9/29/2026 | 10/6/2026 | Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper. | |
| Undergoing Analysis | Critical (9.3) | 0.38% | 💥 PoC | Joomlaboat Youtube GalleryAI | 9/26/2026 | 9/29/2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries. | |
| Undergoing Analysis | High (7.2) | 0.26% | — | Joomla Easy StoreAI | 9/23/2026 | 9/23/2026 | Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core Joomla mail configuration (fromname, mailfrom) in configuration.php without… | |
| Awaiting Analysis | High (8.6) | 0.28% | — | Joomshaper Easy StoreAIJoomlaAI | 9/23/2026 | 9/25/2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) took input IDs and directly concatenated them into raw SQL IN (...) clauses in… | |
| Deferred | Critical (9.4) | 0.64% | — | Ordasoft Joomla GalleryAIJoomlaAI | 9/20/2026 | 9/22/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content… | |
| Deferred | Critical (9.4) | 0.67% | — | Ordasoft Joomla GalleryAIJoomlaAI | 9/20/2026 | 9/22/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a… |