Security Risk Category

Joomla Security Risks — Page 2

Published vulnerability pages connected to Joomla. Each page keeps one canonical URL and focused remediation guidance.

41 published Joomla risks

Joomla risks

Showing 37–41 of 41 published risks.

mediumEPSS 0.003

CVE-2026-48958 Joomla CMS vulnerability

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

CVE-2026-48958joomlaapi-securityauthorization-bypass

Updated Jul 12, 2026

critical

Balbooa Forms Joomla Extension Arbitrary File Upload RCE Vulnerability

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVE-2026-56291joomlaphpremote-code-executionfile-upload

Updated Jul 10, 2026

critical

AcyMailing Joomla Component SQL Injection Vulnerability

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

CVE-2026-56292joomlaphpsql-injection

Updated Jul 10, 2026

criticalCISA KEVEPSS 0.007

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CVE-2026-56290joomlaremote-code-executionauthorization-bypassfile-upload

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.804

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

CVE-2026-48907joomlaphpauthorization-bypass

Updated Jul 9, 2026