Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites with
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Joomla! Project | Joomla! CMS | 1.5.0-5.4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92222 | 8.9 HIGH | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0. |
| CVE-2026-92227 | 8.2 HIGH | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in |
| CVE-2026-92232 | 7.1 HIGH | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace charact |
| CVE-2026-92231 | 7.1 HIGH | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decod |
| CVE-2026-90913 | 7.0 HIGH | Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoin |
| CVE-2026-92226 | 7.0 HIGH | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in |
| CVE-2026-90915 | 7.0 HIGH | Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in |
| CVE-2026-90918 | 6.9 MEDIUM | Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0 |
| CVE-2026-90917 | 6.9 MEDIUM | Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joom |
| CVE-2026-92225 | 5.9 MEDIUM | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 |
| CVE-2026-90906 | 5.9 MEDIUM | Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6. |
| CVE-2026-92224 | 5.9 MEDIUM | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0 |
| CVE-2026-90914 | 5.9 MEDIUM | Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0 |
| CVE-2026-92223 | 5.1 MEDIUM | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Jooml |
| CVE-2026-90916 | 5.1 MEDIUM | Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view |
No comments yet