Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Lack of escaping leads to an XSS vulnerability in the update list view of cominstaller.
An improper access check allows privileged users to overwrite media files without editing permissions.
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Lack of escaping leads to an XSS vulnerability in the file management view of comtemplates.
An improper access check allows unauthorized users to access workflow stage and transition information.
An improper access check allows users to display a list of modules in the frontend.
An improper access check allows unauthorized users to access comprivacy datasets.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
An improper access check allows user to download vcard exports of comcontact contacts that are inaccessible.
Lack of validation leads to an XSS vulnerability in the MFA management views.
Improper validation leads to a generic XSS vector in the language override feature.
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for comfinder.
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of comusers.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Improperly validated order clauses lead to a SQL injection vulnerability in comtags.
An improper validation of the search parameter of the commedia files API endpoint leads to a path traversal vulnerability.
Lack of input filtering leads to an XSS vector in the HTML filter code.