Joomla Security Centre·Aug 17, 2026[20260810] - Core - Unrestricted uploads of SHTML files#cms#code-execution#cve-2026-73373CVE-2026-73373
Joomla Security Centre·Aug 17, 2026[20260809] - Core - Improper ACL checks when injection schema.org contact data#access-control#cve-2026-73372#information-disclosureCVE-2026-73372
Joomla Security Centre·Aug 17, 2026[20260808] - Core - Improper ACL checks for batch copy actions#access-control#cve-2026-73371#joomlaCVE-2026-73371
Joomla Security Centre·Aug 17, 2026[20260807] - Core - MFA Authentication Bypass#2fa#authentication-bypass#cve-2026-73337CVE-2026-73337
Joomla Security Centre·Aug 17, 2026[20260806] - Core - XSS through schema.org outputs#cve-2026-73336#joomla#schema-orgCVE-2026-73336
Joomla Security Centre·Aug 17, 2026[20260805] - Core - Improper ACL checks for category webservice endpoints#access-control#acl#apiCVE-2026-72532
Joomla Security Centre·Aug 17, 2026[20260804] - Core - Improper ACL checks for custom fields webservice endpoints#access-control#acl#cmsCVE-2026-72531
Joomla Security Centre·Aug 17, 2026[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints#access-control#acl#apiCVE-2026-71574
Joomla Security Centre·Aug 17, 2026[20260802] - Core - Improper CORS origin validation#cms#cors#joomlaCVE-2026-71573
Joomla Security Centre·Aug 17, 2026[20260801] - Core - Response header injection in download views#cms#header-injection#joomlaCVE-2026-71572
Exploit-DB·Aug 17, 2026[webapps] Joomla JCE_2.9.15 - Remote Code Execution#exploit#jce#joomlaExploit / PoC1
Rapid7 Blog·Aug 14, 2026Metasploit Wrap Up: Lot of summer shells and fit http profiles#exploit-modules#ghost-cms#joomla