Výsledky hledání

výrobce: Joomla× v celém archivu zrušit filtry

3 karet z 4 položek CZ · EN/orig

1

Joomla JCE: rilevato sfruttamento CVE-2026-48907 al fine di distribuire webshell utilizzate per defacement

Questo CSIRT ha recentemente registrato, nel contesto nazionale, un aumento significativo di sfruttamenti attivi della CVE-2026-48907 – già sanata dal vendor e trattata nell’ambito dell’AL02/260615/CSIRT-ITA – ai danni di server web esposti. Tale vulnerabilità interessa il plugin Joomla Content Editor (JCE), estensione per il noto Content Management System (CMS) Joomla!.

KEV ✓ EPSS 0.78 CVE-2026-48907 Joomla JCE IT

tg: zneužíváno tg: zranitelnost tp: malware

· CSIRT Itálie (ACN) · Joomla JCE: rilevato sfruttamento CVE-2026-48907 al fine di distribuire webshell utilizzate per defacement

1

miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-77995, Summary: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

EPSS 0.00 CVSS 10.0 CVE-2026-77995 Joomla miniOrange FI

tg: zranitelnost tp: identita

· NCSC-FI · miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0

1

SPOJENO PŘES CVE Joomla 6.1.3 & 5.4.8 Security & Bugfix Release

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 8.9, CVEs: CVE-2026-73372, CVE-2026-73336, CVE-2026-72531, CVE-2026-71573, CVE-2026-71572, CVE-2026-73373, CVE-2026-73371, CVE-2026-73337, CVE-2026-72532, CVE-2026-71574, Summary: The Joomla! Project is pleased to announce the release of Joomla 6.1.3 and Joomla 5.4.8. These are security & bugfix releases for the Joomla 5.x and 6.x series.

EPSS 0.00 CVSS 8.9 CVE-2026-71572 CVE-2026-71573 CVE-2026-71574 CVE-2026-72531 CVE-2026-72532 CVE-2026-73336 CVE-2026-73337 CVE-2026-73371 CVE-2026-73372 CVE-2026-73373 Joomla FI FR

· NCSC-FI · Joomla 6.1.3 & 5.4.8 Security & Bugfix Release · CERT-FR – avis · Multiples vulnérabilités dans Joomla! (19 août 2026)