[UPDATE] [medium] Joomla: Multiple vulnerabilities
A remote, authenticated attacker can exploit multiple vulnerabilities in Joomla to conduct attacks such as Cross-Site Scripting (XSS), SQL injection, privilege escalation, authentication bypass, path traversal, local file inclusion (LFI), and unauthorized access.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote, authenticated attackers to conduct various attacks including XSS, SQL injection, and privilege escalation.
- Who is affected
- Authenticated users of Joomla are affected.
- Urgency
- Medium urgency for remediation due to the potential for serious attacks.
- Action
- Update Joomla to the latest version to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Joomla
Get an email when a new Joomla advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1688
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-259000.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-259010.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-308940.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-308950.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-352200.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-352210.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-352220.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-352230.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-403830.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-403840.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
Referenced CVEs
Recent advisories for Joomla
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-77998: Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Par…nvd · 2026-08-25
- unknownCVE-2026-77997: Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme…nvd · 2026-08-25
- unknownCVE-2026-77996: Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5…nvd · 2026-08-25
- unknownCVE-2026-77995: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.…nvd · 2026-08-24
- unknownCVE-2026-77994: Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The J…nvd · 2026-08-24
- unknownCVE-2026-77993: Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extensi…nvd · 2026-08-24
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25