Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the content history component.
Lack of output escaping leads to a XSS vector in the readmore links for comcontent.
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for comfinder.
An improper access check allows unauthorized access to comconfig webservice endpoints.
Improperly validated order clauses lead to a SQL injection vulnerability in comtags.
An improper validation of the search parameter of the commedia files API endpoint leads to a path traversal vulnerability.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
An improper access check allows privilege escalation through the comusers batch task.
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
An improper access check allows privilege escalation through the comusers batch task.
An improper access check allows privelege escalation through the comusers group editing webservice endpoint.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
Lack of output escaping leads to a XSS vector in the feed modules.