Vulnerabilities
Vulnerable Software
Joomla:  >> Joomla!  >> 3.0.3  Security Vulnerabilities
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
CVSS Score
4.8
EPSS Score
0.002
Published
2026-08-18
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
CVSS Score
8.9
EPSS Score
0.004
Published
2026-08-18
Improper validation leads to a generic XSS vector in the language override feature.
CVSS Score
5.9
EPSS Score
0.002
Published
2026-07-07
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVSS Score
6.4
EPSS Score
0.004
Published
2026-07-07
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-05-26
Lack of input filtering leads to an XSS vector in the HTML filter code.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-05-26
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-05-26
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
CVSS Score
6.9
EPSS Score
0.003
Published
2026-05-26
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVSS Score
6.9
EPSS Score
0.003
Published
2026-05-26
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVSS Score
6.9
EPSS Score
0.002
Published
2026-05-26


Contact Us

Shodan ® - All rights reserved