Joomla! Project Joomla! CMS是Joomla! Project的内容管理系统。 Joomla! Project Joomla! CMS存在权限许可和访问控制问题漏洞,该漏洞源于访问控制不当,导致用户能够下载不可访问的com_contact联系人的vcard导出数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Joomla! Project | Joomla! CMS | 3.0.0-5.4.6 |
affected |
6.0.0-6.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Joomla! Project | Joomla! CMS | 3.0.0-5.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48956 | Joomla! Core - [20260710] - Incorrect Access Control in com_modules | |
| CVE-2026-48949 | Joomla! Core - [20260703] - XSS in MFA method management | |
| CVE-2026-48957 | Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints | |
| CVE-2026-48952 | Joomla! Core - [20260706] - XSS in com_installer | |
| CVE-2026-48947 | Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints | |
| CVE-2026-48953 | Joomla! Core - [20260707] - XSS in the generic image output layout | |
| CVE-2026-48950 | Joomla! Core - [20260704] - XSS in com_templates | |
| CVE-2026-48954 | Joomla! Core - [20260708] - XSS through language overrides | |
| CVE-2026-48958 | Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints | |
| CVE-2026-48955 | Joomla! Core - [20260709] - Incorrect Access Control in com_workflow | |
| CVE-2026-48951 | Joomla! Core - [20260705] - XSS in various modalreturn layouts |
No comments yet