Security Risk Category
Joomla Security Risks
Published vulnerability pages connected to Joomla. Each page keeps one canonical URL and focused remediation guidance.
41 published Joomla risks
Joomla risks
Showing 1–36 of 41 published risks.
CVE-2026-65760 Easy Store extension for Joomla vulnerability
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
Updated Jul 24, 2026
CVE-2026-65759 Easy Store extension for Joomla vulnerability
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.
Updated Jul 24, 2026
CVE-2026-65761 Easy Store extension for Joomla vulnerability
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
Updated Jul 24, 2026
CVE-2026-65762 Phoca Guestbook extension for Joomla vulnerability
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Updated Jul 24, 2026
CVE-2026-65763 Phoca Maps extension for Joomla vulnerability
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Updated Jul 24, 2026
CVE-2026-60026 Quix Page Builder Pro extension for Joomla vulnerability
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).
Updated Jul 21, 2026
CVE-2026-60027 Quix Page Builder Pro extension for Joomla vulnerability
The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element.
Updated Jul 21, 2026
CVE-2026-60028 Quix Page Builder Pro extension for Joomla vulnerability
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.
Updated Jul 21, 2026
CVE-2026-60029 Quix Page Builder Pro extension for Joomla vulnerability
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.
Updated Jul 21, 2026
CVE-2026-60030 Quix Page Builder Pro extension for Joomla vulnerability
The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.
Updated Jul 21, 2026
CVE-2026-60031 Quix Page Builder Pro extension for Joomla vulnerability
The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.
Updated Jul 21, 2026
CVE-2026-60032 JMedia extension for Joomla vulnerability
The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
Updated Jul 21, 2026
CVE-2026-61424 DJ-Classifieds extension for Joomla vulnerability
The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
Updated Jul 21, 2026
CVE-2026-60033 JMedia extension for Joomla vulnerability
The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.
Updated Jul 21, 2026
CVE-2026-60034 JMedia extension for Joomla vulnerability
The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
Updated Jul 21, 2026
CVE-2026-61425 Gridbox extension for Joomla vulnerability
The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
Updated Jul 21, 2026
CVE-2026-61900 jDownloads extension for Joomla vulnerability
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Updated Jul 21, 2026
CVE-2026-61901 Hikashop extension for Joomla vulnerability
The Joomla extension Hikashop is vulnerable to an open redirect.
Updated Jul 21, 2026
CVE-2026-62414 Page Builder CK extension for Joomla vulnerability
The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.
Updated Jul 21, 2026
CVE-2026-62415 Membership Pro extension for Joomla vulnerability
The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
Updated Jul 21, 2026
CVE-2026-57827 RSFiles Unauthenticated File Upload RCE Vulnerability
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Updated Jul 15, 2026
CVE-2026-57828 Phoca Download File Upload RCE Vulnerability
The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Updated Jul 15, 2026
CVE-2026-57829 in Helix Ultimate for Joomla
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Updated Jul 15, 2026
CVE-2026-57830 in Helix Ultimate for Joomla
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Updated Jul 15, 2026
CVE-2026-48939 iCagenda for Joomla vulnerability
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Updated Jul 12, 2026
CVE-2026-48947 Joomla CMS vulnerability
An improper access check allows privileged users to overwrite media files without editing permissions.
Updated Jul 12, 2026
CVE-2026-48948 Joomla CMS vulnerability
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Updated Jul 12, 2026
CVE-2026-48949 Joomla CMS vulnerability
Lack of validation leads to an XSS vulnerability in the MFA management views.
Updated Jul 12, 2026
CVE-2026-48950 Joomla CMS vulnerability
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Updated Jul 12, 2026
CVE-2026-48951 Joomla CMS vulnerability
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Updated Jul 12, 2026
CVE-2026-48952 Joomla CMS vulnerability
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Updated Jul 12, 2026
CVE-2026-48953 Joomla CMS vulnerability
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Updated Jul 12, 2026
CVE-2026-48954 Joomla CMS vulnerability
Improper validation leads to a generic XSS vector in the language override feature.
Updated Jul 12, 2026
CVE-2026-48955 Joomla CMS vulnerability
An improper access check allows unauthorized users to access workflow stage and transition information.
Updated Jul 12, 2026
CVE-2026-48956 Joomla CMS vulnerability
An improper access check allows users to display a list of modules in the frontend.
Updated Jul 12, 2026
CVE-2026-48957 Joomla CMS vulnerability
An improper access check allows unauthorized users to access com_privacy datasets.
Updated Jul 12, 2026
