目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Joomla! Project 厂商漏洞列表 / CVE 中文分析 124

Joomla! Project 厂商相关 124 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Joomla! Project 致力于维护基于 PHP 的开源内容管理系统,广泛用于构建各类网站。其历史漏洞多集中于远程代码执行、跨站脚本及越权访问,常因插件或核心组件处理不当引发。尽管项目持续发布安全更新,但过去曾发生多起严重数据泄露事件,促使社区强化代码审计机制。目前收录 82 条 CVE,反映出其作为主流 CMS 在复杂生态下面临的持续安全挑战,用户需及时升级以规避风险。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-71573 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-93 6.9 Medium2026-08-18
CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-284 5.1 Medium2026-08-18
CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-79 5.1 Medium2026-08-18
CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 — Joomla! CMSCWE-284 5.1 Medium2026-08-18
CVE-2026-71572 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-93 4.8 Medium2026-08-18
CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 — Joomla! CMSCWE-287 8.2 High2026-08-18
CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-284 5.1 Medium2026-08-18
CVE-2026-72532 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-284 5.1 Medium2026-08-18
CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-434 8.9 High2026-08-18
CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMSCWE-284 8.5 High2026-08-18
CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48947 Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48958 Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48955 Joomla! Core - [20260709] - Incorrect Access Control in com_workflow — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48948 Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48954 Joomla! Core - [20260708] - XSS through language overrides — Joomla! CMSCWE-79--2026-07-07
CVE-2026-35221 Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder — Joomla! CMSCWE-89--2026-05-26
CVE-2026-48903 Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code. — Joomla! Framework Filter packageCWE-79--2026-05-26
CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass — Joomla! CMSCWE-287--2026-05-26
CVE-2026-35220 Joomla! Core - [20260505] - CSRF in user activation endpoint — Joomla! CMSCWE-352--2026-05-26
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter — Joomla! CMSCWE-22--2026-05-26
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags — Joomla! CMSCWE-89--2026-05-26
CVE-2026-40384 Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint — Joomla! CMSCWE-22--2026-05-26
CVE-2026-48905 Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code. — Joomla! Framework Filter packageCWE-79--2026-05-26

本页汇总了 Joomla! Project 厂商截至目前公开的全部 124 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。