Vulnerabilidades em Joomla! Project

124 resultados
Análise Vexday

O Joomla! Project acumula 102 CVEs catalogadas, com uma taxa de exploração ativa 2,2 vezes acima da média geral do catálogo CISA KEV — sinal de que vulnerabilidades nessa plataforma tendem a ser efetivamente aproveitadas por atores maliciosos. O caso mais crítico em exploração ativa é CVE-2023-23752, com EPSS de 0,9983, indicando probabilidade extremamente elevada de exploração iminente ou em curso, e que deve ser tratada com prioridade máxima em qualquer ambiente Joomla! exposto. A falha mais comum é do tipo CWE-79 (Cross-Site Scripting), o que sugere fragilidades recorrentes na sanitização de entradas e saídas, especialmente relevante em um CMS com ampla superfície de extensões de terceiros. O volume de 26 CVEs surgidas nos últimos 90 dias reforça a necessidade de ciclos contínuos de atualização e monitoramento, sem depender apenas de janelas de manutenção periódicas.

CVE-2026-48951MEDIUMJoomla! Core - [20260705] - XSS in various modalreturn layoutsEPSS 0.2%CVE-2026-48952MEDIUMJoomla! Core - [20260706] - XSS in com_installerEPSS 0.2%CVE-2026-48899MEDIUMJoomla! Core - [20260515] - Incorrect Access Control in sample data pluginsEPSS 0.2%CVE-2023-23750MEDIUM[20230101] - Core - CSRF within post-installation messagesEPSS 0.2%CVE-2026-21631MEDIUMJoomla! Core - [20260303] - XSS vector in com_associations comparison viewEPSS 0.2%CVE-2026-48897HIGHJoomla! Core - [20260512] - MFA Authentication BypassEPSS 0.2%CVE-2025-63083MEDIUMJoomla! Core - [20260102] - XSS vector in the pagebreak pluginEPSS 0.2%CVE-2025-63082MEDIUMJoomla! Core - [20260101] - Inadequate content filtering for data URLsEPSS 0.2%CVE-2026-73371MEDIUMJoomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-73372MEDIUMJoomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2EPSS 0.2%CVE-2026-71574HIGHJoomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-73336MEDIUMJoomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-72531MEDIUMJoomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-72532MEDIUMJoomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-21632MEDIUMJoomla! Core - [20260304] - XSS vectors in various article title outputsEPSS 0.2%CVE-2026-30894MEDIUMJoomla! Core - [20260503] - XSS in com_contenthistoryEPSS 0.2%CVE-2026-25900MEDIUMJoomla! Core - [20260501] - XSS in feed modulesEPSS 0.2%CVE-2026-30895MEDIUMJoomla! Core - [20260504] - XSS in readmore linksEPSS 0.2%CVE-2026-25901MEDIUMJoomla! Core - [20260502] - XSS in com_associationsEPSS 0.2%CVE-2026-71572MEDIUMJoomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%