joomla GeoIP是joomla组织的一款基于IP地址定位地理位置的Web组件。 joomla GeoIP 1.0.0版本至6.3.8版本存在授权问题漏洞,该漏洞源于信任可伪造的转发客户端IP标头进行GeoIP查询,可能导致GeoIP规则绕过。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| regularlabs.com | GeoIP extension for Joomla | 1.0.0-6.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | GeoIP extension for Joomla | 1.0.0-6.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64871 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in | |
| CVE-2026-64872 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension | |
| CVE-2026-64874 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension | |
| CVE-2026-64873 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension | |
| CVE-2026-64799 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere | |
| CVE-2026-64876 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in | |
| CVE-2026-65713 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension | |
| CVE-2026-65431 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension | |
| CVE-2026-65712 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extensio | |
| CVE-2026-65756 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension | |
| CVE-2026-65754 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension | |
| CVE-2026-65757 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in | |
| CVE-2026-65755 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhe | |
| CVE-2026-65430 | Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension |
No comments yet