Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
143021.2%CRITICAL

Related CVEs

43
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-48905Lack of input filtering leads to an XSS vector in the HTML filter code.MEDIUM6.94.0%May 26, 2026
CVE-2026-48904An improper access check allows privelege escalation through the com_users group editing webservice endpoint.HIGH8.220.8%May 26, 2026
CVE-2026-48903Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.MEDIUM6.94.0%May 26, 2026
CVE-2026-48902The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.CRITICAL9.88.8%May 26, 2026
CVE-2026-48901The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.HIGH7.515.6%May 26, 2026
CVE-2026-48900An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.MEDIUM6.45.0%May 26, 2026
CVE-2026-48899An improper access check allows privilege escalation through the com_users batch task.MEDIUM5.314.2%May 26, 2026
CVE-2026-48898An improper access check allows privilege escalation through the com_users batch task.HIGH8.218.4%May 26, 2026
CVE-2026-48897Insufficient state checks lead to a vector that allows to bypass 2FA checks.HIGH8.211.4%May 26, 2026
CVE-2026-48896Insufficient state checks lead to a vector that allows to bypass 2FA checks.HIGH8.221.3%May 26, 2026
CVE-2026-40384An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.MEDIUM5.935.5%May 26, 2026
CVE-2026-40383An improper validation of user-supplied input leads to a local file inclusion vulnerability.HIGH7.537.9%May 26, 2026
CVE-2026-35223An improper access check allows unauthorized access to com_config webservice endpoints.HIGH8.626.7%May 26, 2026
CVE-2026-35222Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.MEDIUM6.922.7%May 26, 2026
CVE-2026-35221Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.MEDIUM6.922.7%May 26, 2026
CVE-2026-35220Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.MEDIUM4.61.2%May 26, 2026
CVE-2026-30895Lack of output escaping leads to a XSS vector in the readmore links for com_content.MEDIUM6.97.2%May 26, 2026
CVE-2026-30894Lack of output escaping leads to a XSS vector in the content history component.MEDIUM6.97.2%May 26, 2026
CVE-2026-25901Lack of output escaping leads to a XSS vector in the multilingual associations component.MEDIUM6.97.2%May 26, 2026
CVE-2026-25900Lack of output escaping leads to a XSS vector in the feed modules.MEDIUM6.97.2%May 26, 2026