← All vendors

joomla

28 known vulnerabilities affecting joomla products.

Products

joomla\! 27 calendar_planner 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-40383 Medium 0.5% 9.8 An improper validation of user-supplied input leads to a local file inclusion vu…
CVE-2026-40384 Medium 0.4% 7.5 An improper validation of the search parameter of the com_media files API endpoi…
CVE-2017-20267 Medium 0.4% 8.2 Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability…
CVE-2026-73373 Medium 0.4% 9.8 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-…
CVE-2026-35223 Medium 0.3% 9.8 An improper access check allows unauthorized access to com_config webservice end…
CVE-2026-35221 Medium 0.3% 9.8 Improperly built filter clauses lead to a SQL injection vulnerability in the sea…
CVE-2026-35222 Medium 0.3% 9.8 Improperly validated order clauses lead to a SQL injection vulnerability in com_…
CVE-2026-48896 Medium 0.3% 7.5 Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48904 Medium 0.3% 9.8 An improper access check allows privelege escalation through the com_users group…
CVE-2026-48898 Medium 0.3% 9.8 An improper access check allows privilege escalation through the com_users batch…
CVE-2026-73337 Medium 0.3% 7.5 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and …
CVE-2026-48902 Medium 0.3% 9.8 The password and username reset features created plain http links for https conn…
CVE-2026-71573 Medium 0.2% 8.3 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.…
CVE-2026-48901 Medium 0.2% 7.5 The InputFilter::getInstance() method omitted a security sensitive parameter fro…
CVE-2026-48899 Medium 0.2% 9.8 An improper access check allows privilege escalation through the com_users batch…
CVE-2026-48897 Medium 0.2% 7.5 Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-73371 Low 0.2% 4.3 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla…
CVE-2026-73372 Low 0.2% 4.3 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contac…
CVE-2026-71574 Low 0.2% 6.5 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endp…
CVE-2026-73336 Low 0.2% 6.4 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7…
CVE-2026-72531 Low 0.2% 5.4 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice end…
CVE-2026-72532 Low 0.2% 5.4 Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoint…
CVE-2026-30894 Low 0.2% 6.1 Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-25901 Low 0.2% 6.1 Lack of output escaping leads to a XSS vector in the multilingual associations c…
CVE-2026-30895 Low 0.2% 6.1 Lack of output escaping leads to a XSS vector in the readmore links for com_cont…
CVE-2026-71572 Low 0.2% 5.4 Joomla! Core - [20260801] - Response header injection in download views in Jooml…
CVE-2026-48900 Low 0.2% 4.3 An improper access check allowed low privileged users to edit the task types of …
CVE-2026-48903 Low 0.1% 6.1 Inadequate content filtering within the checkAttribute methods leads to XSS vuln…