U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:a:joomla:joomla\!:4.2.6:rc1:*:*:*:*:*:*
  • CPE Name Search: true
There are 351 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2025-25227

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Published: April 08, 2025; 1:15:35 PM -0400
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-40749

Improper Access Controls allows access to protected views.

Published: January 07, 2025; 12:15:23 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-40748

Lack of output escaping in the id attribute of menu lists.

Published: January 07, 2025; 12:15:23 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-40747

Various module chromes didn't properly process inputs, leading to XSS vectors.

Published: January 07, 2025; 12:15:23 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-40743

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

Published: August 20, 2024; 12:15:11 PM -0400
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-27187

Improper Access Controls allows backend users to overwrite their username when disallowed.

Published: August 20, 2024; 12:15:10 PM -0400
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-27186

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

Published: August 20, 2024; 12:15:10 PM -0400
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-27185

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

Published: August 20, 2024; 12:15:10 PM -0400
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-27184

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

Published: August 20, 2024; 12:15:10 PM -0400
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-26279

The wrapper extensions do not correctly validate inputs, leading to XSS vectors.

Published: July 09, 2024; 1:15:15 PM -0400
V4.0:(not available)
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2024-26278

The Custom Fields component not correctly filter inputs, leading to a XSS vector.

Published: July 09, 2024; 1:15:14 PM -0400
V4.0:(not available)
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2024-21731

Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.

Published: July 09, 2024; 1:15:14 PM -0400
V4.0:(not available)
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2024-21730

The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.

Published: July 09, 2024; 1:15:14 PM -0400
V4.0:(not available)
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2024-21729

Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

Published: July 09, 2024; 1:15:14 PM -0400
V4.0:(not available)
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2024-21726

Inadequate content filtering leads to XSS vulnerabilities in various components.

Published: February 28, 2024; 8:44:03 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-21725

Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.

Published: February 28, 2024; 8:44:03 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-21724

Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.

Published: February 28, 2024; 8:44:03 PM -0500
V4.0:(not available)
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2024-21723

Inadequate parsing of URLs could result into an open redirect.

Published: February 28, 2024; 8:44:03 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-21722

The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

Published: February 28, 2024; 8:44:03 PM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-40626

The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

Published: November 29, 2023; 8:15:07 AM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)