Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
An improper access check allows privileged users to overwrite media files without editing permissions.
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
An improper access check allows unauthorized users to access workflow stage and transition information.
An improper access check allows unauthorized users to access comprivacy datasets.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
An improper access check allows user to download vcard exports of comcontact contacts that are inaccessible.