Multiple vulnerabilities in Joomla! (August 19, 2026)
Multiple vulnerabilities have been discovered in Joomla!. Some of them allow an attacker to cause remote arbitrary code execution, data integrity breach and remote indirect code injection (XSS).
CSIRTS triage
- What
- Multiple vulnerabilities enable remote arbitrary code execution, data integrity breach, and remote indirect code injection via XSS.
- Who is affected
- Joomla deployments running affected versions.
- Urgency
- Critical; remote arbitrary code execution vulnerabilities require immediate patching to prevent system compromise.
- Action
- Update Joomla to the latest patched version addressing all listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Joomla
Get an email when a new Joomla advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1046/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-733710.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733370.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733360.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-715740.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-715720.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-725320.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733730.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-725310.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-715730.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-733720.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-73371 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73336 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71574 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71572 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-72532 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73373 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-72531 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71573 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73372 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Joomla: Multiple vulnerabilitiescert-bund
- unknownCVE-2026-73372: Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joom…nvd
- unknownCVE-2026-73336: Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 …nvd
- unknownCVE-2026-72531: Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joom…nvd
- unknownCVE-2026-71573: Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2…nvd
- unknownCVE-2026-71572: Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7,…nvd
- unknownCVE-2026-73373: Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6…nvd
- unknownCVE-2026-73371: Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, …nvd
- unknownCVE-2026-73337: Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - …nvd
- unknownCVE-2026-72532: Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.…nvd
- unknownCVE-2026-71574: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Jooml…nvd
Recent advisories for Joomla!
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-78080: Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - T…nvd · 2026-09-03
- unknownCVE-2026-78069: Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain …nvd · 2026-09-03
- unknownCVE-2026-78065: Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated use…nvd · 2026-09-03
- unknownCVE-2026-78064: Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` t…nvd · 2026-09-03
- unknownCVE-2026-78000: Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` …nvd · 2026-09-03
- unknownCVE-2026-77999: Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order c…nvd · 2026-09-03
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Typo3 (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans les produits SAP (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans Mattermost Server (08 septembre 2026)2026-09-08
- unknownVulnérabilité dans les produits Adobe (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans strongSwan (08 septembre 2026)2026-09-08