Security Risk Category

Joomla Security Risks

Published vulnerability pages connected to Joomla. Each page keeps one canonical URL and focused remediation guidance.

41 published Joomla risks

Joomla risks

Showing 1–36 of 41 published risks.

critical

CVE-2026-65760 Easy Store extension for Joomla vulnerability

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

CVE-2026-65760joomlaauthorization-bypassinformation-disclosure

Updated Jul 24, 2026

high

CVE-2026-65759 Easy Store extension for Joomla vulnerability

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.

CVE-2026-65759joomlaauthorization-bypass

Updated Jul 24, 2026

critical

CVE-2026-65761 Easy Store extension for Joomla vulnerability

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

CVE-2026-65761joomlasql-injection

Updated Jul 24, 2026

medium

CVE-2026-65762 Phoca Guestbook extension for Joomla vulnerability

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.

CVE-2026-65762joomlaxss

Updated Jul 24, 2026

medium

CVE-2026-65763 Phoca Maps extension for Joomla vulnerability

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.

CVE-2026-65763joomlaxss

Updated Jul 24, 2026

high

CVE-2026-60026 Quix Page Builder Pro extension for Joomla vulnerability

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).

CVE-2026-60026joomlaphpremote-code-execution

Updated Jul 21, 2026

high

CVE-2026-60027 Quix Page Builder Pro extension for Joomla vulnerability

The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element.

CVE-2026-60027joomlapath-traversalfile-write

Updated Jul 21, 2026

high

CVE-2026-60028 Quix Page Builder Pro extension for Joomla vulnerability

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.

CVE-2026-60028joomlaxss

Updated Jul 21, 2026

medium

CVE-2026-60029 Quix Page Builder Pro extension for Joomla vulnerability

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

CVE-2026-60029joomlaxss

Updated Jul 21, 2026

high

CVE-2026-60030 Quix Page Builder Pro extension for Joomla vulnerability

The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.

CVE-2026-60030joomlaauthorization-bypass

Updated Jul 21, 2026

medium

CVE-2026-60031 Quix Page Builder Pro extension for Joomla vulnerability

The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

CVE-2026-60031joomlainformation-disclosure

Updated Jul 21, 2026

critical

CVE-2026-60032 JMedia extension for Joomla vulnerability

The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.

CVE-2026-60032joomlaremote-code-executionfile-uploadfile-write

Updated Jul 21, 2026

critical

CVE-2026-61424 DJ-Classifieds extension for Joomla vulnerability

The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

CVE-2026-61424joomlaremote-code-executionfile-upload

Updated Jul 21, 2026

medium

CVE-2026-60033 JMedia extension for Joomla vulnerability

The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.

CVE-2026-60033joomlassrf

Updated Jul 21, 2026

critical

CVE-2026-60034 JMedia extension for Joomla vulnerability

The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.

CVE-2026-60034joomlaxss

Updated Jul 21, 2026

critical

CVE-2026-61425 Gridbox extension for Joomla vulnerability

The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

CVE-2026-61425joomlaauthentication-bypass

Updated Jul 21, 2026

critical

CVE-2026-61900 jDownloads extension for Joomla vulnerability

The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

CVE-2026-61900joomlaremote-code-executionfile-upload

Updated Jul 21, 2026

medium

CVE-2026-61901 Hikashop extension for Joomla vulnerability

The Joomla extension Hikashop is vulnerable to an open redirect.

CVE-2026-61901joomlaopen-redirect

Updated Jul 21, 2026

medium

CVE-2026-62414 Page Builder CK extension for Joomla vulnerability

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

CVE-2026-62414joomlaauthorization-bypass

Updated Jul 21, 2026

medium

CVE-2026-62415 Membership Pro extension for Joomla vulnerability

The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

CVE-2026-62415joomla

Updated Jul 21, 2026

criticalEPSS 0.003

CVE-2026-57827 RSFiles Unauthenticated File Upload RCE Vulnerability

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVE-2026-57827joomlaweb-applicationremote-code-executionfile-upload

Updated Jul 15, 2026

criticalEPSS 0.003

CVE-2026-57828 Phoca Download File Upload RCE Vulnerability

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

CVE-2026-57828joomlaweb-applicationremote-code-executionfile-upload

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-57829 in Helix Ultimate for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

CVE-2026-57829joomlaxssauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57830 in Helix Ultimate for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

CVE-2026-57830joomlaauthorization-bypassfile-writefile-deletion

Updated Jul 15, 2026

criticalCISA KEVEPSS 0.015

CVE-2026-48939 iCagenda for Joomla vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVE-2026-48939joomlaphpweb-applicationremote-code-execution

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48947 Joomla CMS vulnerability

An improper access check allows privileged users to overwrite media files without editing permissions.

CVE-2026-48947joomlaapi-securityauthorization-bypassfile-write

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48948 Joomla CMS vulnerability

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

CVE-2026-48948joomlaauthorization-bypassinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48949 Joomla CMS vulnerability

Lack of validation leads to an XSS vulnerability in the MFA management views.

CVE-2026-48949joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48950 Joomla CMS vulnerability

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

CVE-2026-48950joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48951 Joomla CMS vulnerability

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

CVE-2026-48951joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48952 Joomla CMS vulnerability

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

CVE-2026-48952joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48953 Joomla CMS vulnerability

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

CVE-2026-48953joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48954 Joomla CMS vulnerability

Improper validation leads to a generic XSS vector in the language override feature.

CVE-2026-48954joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48955 Joomla CMS vulnerability

An improper access check allows unauthorized users to access workflow stage and transition information.

CVE-2026-48955joomlaauthorization-bypassinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48956 Joomla CMS vulnerability

An improper access check allows users to display a list of modules in the frontend.

CVE-2026-48956joomlaauthorization-bypassinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48957 Joomla CMS vulnerability

An improper access check allows unauthorized users to access com_privacy datasets.

CVE-2026-48957joomlaapi-securityauthorization-bypassinformation-disclosure

Updated Jul 12, 2026