In iCagenda component for Joomla versions 4.0.8 to 4.0.12 a high severity vulnerability CVE-2026-75948 was detected. This vulnerability allows an authenticated attacker to inject malicious scripts. To address this issue, users should upgrade iCagenda to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-75948.
Read more CMSIn Phoca Cart component for Joomla versions 5.0.0 through 6.1.7 a medium severity vulnerability CVE-2026-76565 was detected. This vulnerability allows attackers to execute arbitrary web scripts. To address this issue, users should upgrade Phoca Cart to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76565.
Read more CMSIn Zoo component for Joomla versions before 4.1.65 a medium severity vulnerability CVE-2026-76610 was detected. This vulnerability allows unauthenticated users to modify tags. To address this issue, users should upgrade Zoo to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76610.
Read more CMSIn YITH WooCommerce Membership Premium component for WooCommerce versions 2.33.0 and earlier a high severity vulnerability CVE-2026-32552 was detected. This vulnerability allows attackers to execute arbitrary SQL commands. To address this issue, users should upgrade YITH WooCommerce Membership Premium to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32552.
Read more E-commerceIn Balbooa Forms component for Joomla versions prior to 2.4.3.2 a high severity vulnerability CVE-2026-67363 was detected. This vulnerability allows an attacker to tamper with payment amounts without authentication. To address this issue, users should upgrade Balbooa Forms to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-67363.
Read more CMSIn Flexible Subscriptions component for WordPress versions 1.8.1 and earlier a critical severity vulnerability CVE-2026-73364 was detected. This vulnerability allows attackers to inject malicious objects. To address this issue, users should upgrade Flexible Subscriptions to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73364.
Read more CMSIn the Balbooa Forms component for Joomla versions 2.4.3.1 and earlier a critical severity vulnerability CVE-2026-67364 was detected. This vulnerability allows an unauthenticated attacker to execute arbitrary PHP code on the server. To address this issue, users should upgrade Balbooa Forms to version 2.4.3.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-67364.
Read more CMSIn Taxi Booking Manager for WooCommerce component for WooCommerce versions before 2.0.8 a medium severity vulnerability CVE-2026-73363 was detected. This vulnerability allows unauthenticated attackers to bypass access controls. To address this issue, users should upgrade Taxi Booking Manager for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73363.
Read more E-commerceIn Keycloak versions prior to the latest patch a medium severity vulnerability CVE-2026-19608 was detected. This vulnerability allows an attacker to potentially bypass group-based access control policies. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19608.
Read more Security