ZeroHour

Search: “cms”

13 stories

[20260810] - Core - Unrestricted uploads of SHTML files

Joomla fixed CVE-2026-73373, an unrestricted SHTML file upload flaw affecting CMS 1.0.0-5.4.7 and 6.0.0-6.1.2 that can enable code execution.

Joomla published security advisory 20260810 for CVE-2026-73373, an unrestricted upload of files with dangerous type in Joomla CMS. The default dangerous-file list omitted SHTML files, which could lead to code execution on servers that execute SHTML. Affected versions are 1.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Valentin Lobstein (Chocapikk) on 2026-07-29.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-73373

[20260809] - Core - Improper ACL checks when injection schema.org contact data

Joomla fixed CVE-2026-73372, an improper ACL check that leaks inaccessible contact items' data into schema.org snippets, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260809 describes CVE-2026-73372, an incorrect access control issue when injecting schema.org contact data. Improper access checks inject contact information for inaccessible contact items into schema.org snippets, exposing restricted data. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Stefan Wendhausen on 2026-07-31.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-73372

[20260808] - Core - Improper ACL checks for batch copy actions

Joomla fixed CVE-2026-73371, an improper ACL check letting unauthorized users batch-copy uneditable items in Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260808 describes CVE-2026-73371, an incorrect access control issue in batch copy actions. The flaw allows unauthorized users to perform copy batch operations on items they cannot edit. Affected versions are 4.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Sabuhi Mammadov on 2026-07-28.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-73371

[20260807] - Core - MFA Authentication Bypass

Joomla fixed CVE-2026-73337, an MFA authentication bypass caused by insufficient state checks, affecting Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260807 describes CVE-2026-73337, an authentication bypass in Joomla CMS multi-factor authentication. Insufficient state checks create a vector that allows 2FA checks to be bypassed; the vendor rates the impact as high with moderate probability. Affected versions are 4.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by bloman and Matej Rada on 2026-07-25.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-73337

[20260806] - Core - XSS through schema.org outputs

Joomla fixed CVE-2026-73336, an XSS in schema.org markup outputs caused by improper escaping, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260806 describes CVE-2026-73336, a cross-site scripting issue in schema.org markup outputs. Improper escaping flags create an XSS vector in schema.org output; the vendor rates impact and severity as moderate with low probability. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Amin Isayev and Geo (GitHub.com/geo-chen) on 2026-07-21.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-73336

[20260805] - Core - Improper ACL checks for category webservice endpoints

Joomla fixes CVE-2026-72532, an improper ACL check letting unauthorized users create categories via webservice endpoints, in CMS 5.4.8/6.1.3.

Joomla disclosed an incorrect access control flaw (CVE-2026-72532) in category webservice endpoints, allowing unauthorized users to create categories for inaccessible components. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2 and is rated moderate impact and severity with low probability. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18; it was reported by Amin Isayev and Geo.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-72532

[20260804] - Core - Improper ACL checks for custom fields webservice endpoints

Joomla patches CVE-2026-72531, an improper ACL check allowing unauthorized custom-field creation via webservice endpoints, in CMS 5.4.8/6.1.3.

Joomla disclosed an incorrect access control issue (CVE-2026-72531) letting unauthorized users create custom fields for inaccessible components through webservice endpoints. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2, rated moderate impact and severity with low probability. Fixed in Joomla 5.4.8 and 6.1.3; reported by ebadfd on 2026-07-06.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-72531

[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints

Joomla fixes CVE-2026-71574, inconsistent ACL checks letting unauthorized users mutate data via webservice APIs, in CMS 5.4.8/6.1.3.

Joomla disclosed an inconsistent access control flaw (CVE-2026-71574) in mutating webservice endpoints, where unauthorized users could perform mutations restricted in the backend UI; impact is rated high. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2, with moderate severity and low probability. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-71574

[20260802] - Core - Improper CORS origin validation

Joomla patches CVE-2026-71573, improper CORS origin validation in CMS requests, in versions 5.4.8 and 6.1.3.

Joomla disclosed improper CORS origin validation (CVE-2026-71573), where configured CORS origins were not properly validated on CORS requests, rated moderate impact/severity and moderate probability. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2. Fixed in Joomla 5.4.8 and 6.1.3; reported on 2026-07-09 by Agamemnon Fakas and caveeroo.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-71573

[20260801] - Core - Response header injection in download views

Joomla fixes CVE-2026-71572, response header injection in download views enabling reflected file download attacks, in 5.4.8/6.1.3.

Joomla disclosed a response header injection flaw (CVE-2026-71572) in multiple download views, caused by lack of output processing, enabling reflected file download and content-type confusion. It is rated low impact, severity, and probability and affects Joomla CMS 3.0.0-5.4.7 and 6.0.0-6.1.2. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18.

Joomla Security Centre · Aug 17, 2026AdvisoryCVE-2026-71572

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 fixes 28 security bugs, including nine crash-prone capture file parsers, misdecoded 5G fields, and memory-safety issues.

Wireshark 4.6.8 fixes 28 security bugs spanning advisories wnpa-sec-2026-64 through wnpa-sec-2026-91, including nine crash bugs in file parsers such as pcapng, Endace ERF and Tektronix K12xx that trigger when opening capture files. Fixes cover dissectors for RDP, SSH, Kerberos, H.245, CMS, C12.22 and several Bluetooth protocols, plus unnumbered memory-safety issues like a stack buffer overflow in the K12/RF5 writer. The release also corrects eight misdecoded 5G NAS/5GSM fields and moves the Unix extcap path to /usr/libexec/wireshark/extcap.

Help Net Security · Aug 13, 2026Advisory