Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Joomla" — 90 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Crítico vulnerabilidad
22/07/2026
[CVE-2026-64796] Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free di…
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured inc…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64797] Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trus…
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
M Crítico vulnerabilidad
22/07/2026
[CVE-2026-64798] Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL …
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63265] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Re…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations out…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63280] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63683] Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions man…
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63047] Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Bo…
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-62415] Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Jo…
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
M Crítico vulnerabilidad
20/07/2026
[CVE-2026-62414] Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla ext…
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-60024] Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Jo…
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
M Alto vulnerabilidad
17/07/2026
[CVE-2026-60025] Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extens…
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
O Crítico vulnerabilidad
13/07/2026
[CVE-2026-57830] Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.…
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
P Alto vulnerabilidad
11/07/2026
[CVE-2026-57828] Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla ex…
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
R Crítico vulnerabilidad
11/07/2026
[CVE-2026-57827] Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The J…
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
A Alto vulnerabilidad
09/07/2026
[CVE-2026-56292] Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnera…
Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
J Alto vulnerabilidad
07/07/2026
[CVE-2026-48957] An improper access check allows unauthorized users to access com_privacy datasets.
An improper access check allows unauthorized users to access com_privacy datasets.
J Alto vulnerabilidad
07/07/2026
[CVE-2026-48958] An improper access check allows unauthorized users to create custom fields via webservices endpoints…
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
J Alto vulnerabilidad
07/07/2026
[CVE-2026-48948] An improper access check allows user to download vcard exports of com_contact contacts that are inac…
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
J Alto vulnerabilidad
07/07/2026
[CVE-2026-56290] Vulnerabilidad explotada activamente en Joomlack Page Builder
CISA confirma explotación activa de una vulnerabilidad en Joomlack Page Builder. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-10.
O Alto vulnerabilidad
29/06/2026
[CVE-2026-49049] The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to …
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.