Vulnerabilidades en Joomla! Project

124 resultados
Análisis Vexday

O Joomla! Project acumula 102 CVEs catalogadas, com uma taxa de exploração ativa 2,2 vezes acima da média geral do catálogo CISA KEV — sinal de que vulnerabilidades nessa plataforma tendem a ser efetivamente aproveitadas por atores maliciosos. O caso mais crítico em exploração ativa é CVE-2023-23752, com EPSS de 0,9983, indicando probabilidade extremamente elevada de exploração iminente ou em curso, e que deve ser tratada com prioridade máxima em qualquer ambiente Joomla! exposto. A falha mais comum é do tipo CWE-79 (Cross-Site Scripting), o que sugere fragilidades recorrentes na sanitização de entradas e saídas, especialmente relevante em um CMS com ampla superfície de extensões de terceiros. O volume de 26 CVEs surgidas nos últimos 90 dias reforça a necessidade de ciclos contínuos de atualização e monitoramento, sem depender apenas de janelas de manutenção periódicas.

CVE-2022-27913—[20221002] - Core - RXSS through reflection of user input in headingsEPSS 0.4%CVE-2024-40749HIGH[20250103] - Core - Read ACL violation in multiple core viewsEPSS 0.4%CVE-2026-48896HIGHJoomla! Core - [20260511] - MFA Authentication BypassEPSS 0.4%CVE-2026-48897HIGHJoomla! Core - [20260512] - MFA Authentication BypassEPSS 0.4%CVE-2024-27187HIGH[20240804] - Core - Improper ACL for backend profile viewEPSS 0.4%CVE-2026-48955MEDIUMJoomla! Core - [20260709] - Incorrect Access Control in com_workflowEPSS 0.3%CVE-2026-71574HIGHJoomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.3%CVE-2026-71573MEDIUMJoomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.3%CVE-2026-21630MEDIUMJoomla! Core - [20260302] - SQL injection in com_content articles webservice endpointEPSS 0.3%CVE-2026-48947MEDIUMJoomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpointsEPSS 0.3%CVE-2026-48902CRITICALJoomla! Core - [20260518] - Transport encryption downgrade for password and username reset linksEPSS 0.3%CVE-2025-54476MEDIUMJoomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter codeEPSS 0.3%CVE-2026-73371MEDIUMJoomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.3%CVE-2026-73372MEDIUMJoomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2EPSS 0.3%CVE-2025-54477MEDIUMJoomla! Core - [20250902] User-Enumeration in passkey authentication methodEPSS 0.3%CVE-2026-48956MEDIUMJoomla! Core - [20260710] - Incorrect Access Control in com_modulesEPSS 0.3%CVE-2024-40743MEDIUM[20240805] - Core - XSS vectors in Outputfilter::strip* methodsEPSS 0.3%CVE-2024-27186MEDIUM[20240803] - Core - XSS in HTML Mail TemplatesEPSS 0.3%CVE-2026-73336MEDIUMJoomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2EPSS 0.3%CVE-2026-72531MEDIUMJoomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.3%