Anuncios de seguridad Joomla
-
[20260810] - Core - Unrestricted uploads of SHTML files
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Probability: Low
- Versions: 1.0.0-5.4.7,6.0.0-6.1.2
- Exploit type: Unrestricted Upload of File with Dangerous Type
- Reported Date: 2026-07-29
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73373
Description
The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.Affected Installs
Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
Reported By: Valentin Lobstein (Chocapikk) -
[20260809] - Core - Improper ACL checks when injection schema.org contact data
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Probability: Low
- Versions: 5.1.0-5.4.7,6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-31
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73372
Description
An improper access check injects contact information for unaccessible contact items into schema.org snippets.Affected Installs
Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
Reported By: Stefan Wendhausen -
[20260808] - Core - Improper ACL checks for batch copy actions
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Probability: Low
- Versions: 4.0.0-5.4.7,6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-28
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73371
Description
An improper access check allows unauthorized users to perform copy batch operations on uneditable items.Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
Reported By: Sabuhi Mammadov -
[20260807] - Core - MFA Authentication Bypass
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.7,6.0.0-6.1.2
- Exploit type: Authentication Bypass
- Reported Date: 2026-07-25
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73337
Description
Insufficient state checks lead to a vector that allows to bypass 2FA checks.Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
Reported By: bloman, Matej Rada -
[20260806] - Core - XSS through schema.org outputs
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
- Exploit type: XSS
- Reported Date: 2026-07-21
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73336
Description
Improper escaping flags lead to an XSS vector in schema.org markup outputs.Affected Installs
Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
Reported By: Amin İsayev, Geo (GitHub.com/geo-chen)
