Vulnerabilities
Vulnerable Software
Joomla:  >> Joomla!  >> 4.0.3  Security Vulnerabilities
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-05-26
Lack of input filtering leads to an XSS vector in the HTML filter code.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-05-26
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-05-26
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVSS Score
8.2
EPSS Score
0.002
Published
2026-05-26
An improper access check allows privilege escalation through the com_users batch task.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-05-26
An improper access check allows privilege escalation through the com_users batch task.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-05-26
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-05-26
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-05-26
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-05-26
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
CVSS Score
5.9
EPSS Score
0.004
Published
2026-05-26


Contact Us

Shodan ® - All rights reserved