MIDOSSA Technical Support

Latest Vulnerabilities

Live defensive vulnerability intelligence for WordPress, Joomla and PrestaShop with severity, affected versions, fixes and official sources.

Start with the symptom.

Send us the website URL, the exact error if available and a short description of what changed.

Latest WordPress, Joomla & PrestaShop Vulnerabilities

Follow recent public security advisories relevant to the CMS platforms and hosting environments MIDOSSA supports. This page is built for defensive awareness: affected software, severity, published date, fixed versions when available and the official advisory source.

Defensive intelligence only

No exploit payloads or attack instructions are published here. Always verify the official advisory before making production changes.

Live security feed

Latest Vulnerabilities

Last synchronized: September 12, 2026 4:12 am

Source titles are kept in their original language to preserve technical accuracy.

Joomla Low

[20260810] - Core - Unrestricted uploads of SHTML files

CVE-2026-73373 Published 2026-08-17

Package: Joomla CMS

Affected:  1.0.0-5.4.7,6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Low

[20260809] - Core - Improper ACL checks when injection schema.org contact data

CVE-2026-73372 Published 2026-08-17

Package: Joomla CMS

Affected:  5.1.0-5.4.7,6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Low

[20260808] - Core - Improper ACL checks for batch copy actions

CVE-2026-73371 Published 2026-08-17

Package: Joomla CMS

Affected:  4.0.0-5.4.7,6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260807] - Core - MFA Authentication Bypass

CVE-2026-73337 Published 2026-08-17

Package: Joomla CMS

Affected:  4.0.0-5.4.7,6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260806] - Core - XSS through schema.org outputs

CVE-2026-73336 Published 2026-08-17

Package: Joomla CMS

Affected:  5.1.0-5.4.7, 6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260805] - Core - Improper ACL checks for category webservice endpoints

CVE-2026-72532 Published 2026-08-17

Package: Joomla CMS

Affected:  4.0.0-5.4.7, 6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260804] - Core - Improper ACL checks for custom fields webservice endpoints

CVE-2026-72531 Published 2026-08-17

Package: Joomla CMS

Affected:  4.0.0-5.4.7, 6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints

CVE-2026-71574 Published 2026-08-17

Package: Joomla CMS

Affected:  4.0.0-5.4.7, 6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260802] - Core - Improper CORS origin validation

CVE-2026-71573 Published 2026-08-17

Package: Joomla CMS

Affected:  4.0.0-5.4.7, 6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
Joomla Low

[20260801] - Core - Response header injection in download views

CVE-2026-71572 Published 2026-08-17

Package: Joomla CMS

Affected:  3.0.0-5.4.7, 6.0.0-6.1.2

Fixed: Upgrade to version 5.4.8, 6.1.3

Source: Joomla Security CentreView official advisory →
WordPress Medium

WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)

CVE-2026-54768 Published 2026-07-31

Package: wp-graphql/wp-graphql

Affected: <= 2.6.0

Source: GitHub Advisory DatabaseView official advisory →
Joomla Medium

[20260705] - Core - XSS in various modalreturn layouts

CVE-2026-48951 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260704] - Core - XSS in com_templates

CVE-2026-48950 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260707] - Core - XSS in the generic image output layout

CVE-2026-48953 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260706] - Core - XSS in com_installer

CVE-2026-48952 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260708] - Core - XSS through language overrides

CVE-2026-48954 Published 2026-07-07

Package: Joomla CMS

Affected:  3.0.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260709] - Core - Incorrect Access Control in com_workflow

CVE-2026-48955 Published 2026-07-07

Package: Joomla CMS

Affected:  6.0.0-6.1.1

Fixed: Upgrade to version 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260703] - Core - XSS in MFA method management

CVE-2026-48949 Published 2026-07-07

Package: Joomla CMS

Affected:  4.2.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260711] - Core - Incorrect Access Control in com_privacy webservice endpoints

CVE-2026-48957 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6, 6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Low

[20260701] - Core - Incorrect Access Control in com_media webservice endpoints

CVE-2026-48947 Published 2026-07-07

Package: Joomla CMS

Affected:  4.1.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Low

[20260702] - Core - Incorrect Access Control in com_contact vcf download

CVE-2026-48948 Published 2026-07-07

Package: Joomla CMS

Affected:  3.0.0-5.4.6,6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260712] - Core - Incorrect Access Control in com_fields webservice endpoints

CVE-2026-48958 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6, 6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260710] - Core - Incorrect Access Control in com_modules

CVE-2026-48956 Published 2026-07-07

Package: Joomla CMS

Affected:  4.0.0-5.4.6, 6.0.0-6.1.1

Fixed: Upgrade to version 5.4.7, 6.1.2

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260520] - Framework - Inadequate content filtering within the cleanAttributes filter code

CVE-2026-48905 Published 2026-05-26

Package: Joomla CMS

Affected:  3.0.0-5.4.5,6.0.0-6.1.0

Fixed: Upgrade to version 5.4.6,6.1.1

Source: Joomla Security CentreView official advisory →
Joomla Medium

[20260519] - Framework - Inadequate content filtering within the checkAttribute filter code

CVE-2026-48903 Published 2026-05-26

Package: Joomla CMS

Affected:  3.0.0-5.4.5,6.0.0-6.1.0

Fixed: Upgrade to version 5.4.6,6.1.1

Source: Joomla Security CentreView official advisory →
Joomla Low

[20260518] - Core - Transport encryption downgrade for password and username reset links

CVE-2026-48902 Published 2026-05-26

Package: Joomla CMS

Affected:  3.9.0-5.4.5,6.0.0-6.1.0

Fixed: Upgrade to version 5.4.6,6.1.1

Source: Joomla Security CentreView official advisory →
Security Assessment

Is my website affected?

Security Assessment

How to use this vulnerability feed

1. Identify your platform

Filter WordPress, Joomla or PrestaShop and search for a product, package or CVE identifier.

2. Check affected versions

Compare the advisory with the CMS, plugin, extension, module or package version running on your website.

3. Patch and verify

Use the vendor’s official remediation guidance, create a recoverable backup and test important functionality after updates.

Authoritative sources & refresh

The live feed uses public defensive advisories from the GitHub Advisory Database and the Joomla Security Centre. Results are refreshed automatically and cached briefly to protect source services and keep this page fast. Coverage is informational and is not guaranteed to include every vulnerability affecting every plugin, extension or module.

Not sure whether your website is affected?

Send us your website URL, CMS and version information. MIDOSSA can perform a deeper security assessment and recommend the safest remediation path.

Request Technical Support

WhatsApp Support