Kwetsbare plugins Joomla! en Wordpress
Kwetsbare plugins afgelopen maand
-
Gridbox (com_gridbox) 2.20.3.1 to 2.20.3.x - Language Installation CSRF and Image Preview Path Validation (fixed in 2.20.4.0)
08 oktober 2026
-
Joomill Admin Checklist (com_checklist) below 1.7.0 - Authenticated Stored XSS via Custom CSS Setting
07 oktober 2026
-
Joomill Admin Checklist (com_checklist) below 1.7.0 - Authenticated Stored XSS via Custom CSS Setting
07 oktober 2026
-
JCH Optimize (com_jchoptimize) below 9.4.0 - Unauthenticated XSS and Page Cache Hit Counter Access Control Bypass, plus Admin CSRF and Open Redirect
07 oktober 2026
-
JCH Optimize (com_jchoptimize) below 9.4.0 - Unauthenticated XSS and Page Cache Hit Counter Access Control Bypass, plus Admin CSRF and Open Redirect
07 oktober 2026
-
OrdaSoft Simple Membership (com_simplemembership) below 7.4.0 - Unauthenticated SQL Injection
07 oktober 2026
-
OrdaSoft Simple Membership (com_simplemembership) below 7.4.0 - Unauthenticated SQL Injection
07 oktober 2026
-
OrdaSoft Touch Slider (mod_os_touchslider) below 5.4.6 - Unauthenticated Slider Image Deletion and Content Replacement
07 oktober 2026
-
OrdaSoft Touch Slider (mod_os_touchslider) below 5.4.6 - Unauthenticated Slider Image Deletion and Content Replacement
07 oktober 2026
-
SP Page Builder (com_sppagebuilder) 5.5.0 to 5.7.x - Unauthenticated Reflected XSS in the Dynamic Content Filter addon (CVE-2026-102426)
05 oktober 2026
-
TF Content (com_tfcontent) 2.9.0 to 2.9.4 - Unauthenticated Forced Execution of Automation Tasks and Record Tampering (Missing Authorisation)
05 oktober 2026
-
OS CCK (com_os_cck) below 8.3.16 - Unauthenticated SQL Injection in record sorting (CVE-2026-102428)
05 oktober 2026
-
Event Gallery (com_eventgallery) below 6.6.0 - CSRF in Backend List Actions, Google Photos Token Leak (SSRF) and Reflected XSS
04 oktober 2026
-
Phoca Cart (com_phocacart) below 6.1.9 - Unauthenticated Order Download IDOR (paid file disclosure)
01 oktober 2026
-
OS CCK (com_os_cck) below 8.3.16 - Unauthenticated Arbitrary File Upload (RCE)
30 september 2026
-
JCTables (com_jctables) below 1.21.1 - Unauthenticated SQL Injection (database read and write, leading to RCE)
30 september 2026
-
Balbooa Forms (com_baforms) below 2.4.3.4 - Unauthenticated PHP Code Injection (RCE), Local File Disclosure via Auto-Reply Attachments, Stored XSS and Attachment Deletion
29 september 2026
-
Book Library (com_booklibrary) below 6.4.6 - Reflected Cross-Site Scripting
28 september 2026
-
Book Library (com_booklibrary) below 6.4.6 - Unauthenticated SQL Injection
28 september 2026
-
Vehicle Manager (com_vehiclemanager) below 6.5.8 - Reflected Cross-Site Scripting
28 september 2026
-
Vehicle Manager (com_vehiclemanager) below 6.5.8 - Unauthenticated SQL Injection
28 september 2026
-
Real Estate Manager (com_realestatemanager) below 6.7.9 - Reflected Cross-Site Scripting
28 september 2026
-
Real Estate Manager (com_realestatemanager) below 6.7.9 - Unauthenticated SQL Injection
28 september 2026
-
Tabs & Accordions (tabsaccordions) 2.3.0 to below 3.2.0 - Authenticated Stored XSS via JavaScript URLs in data-rlta-url Attributes
27 september 2026
-
Tabs & Accordions (tabsaccordions) 2.3.0 to below 3.2.0 - Authenticated Stored XSS via JavaScript URLs in data-rlta-url Attributes
27 september 2026
-
Tabs & Accordions (tabsaccordions) 2.3.0 to below 3.2.0 - Authenticated Stored XSS via JavaScript URLs in data-rlta-url Attributes
27 september 2026
-
Modules Anywhere (modulesanywhere) 1.5.0 to below 10.0.0 - Server-Side Request Forgery and Local File Read via Module Parameter Overrides
27 september 2026
-
Modules Anywhere (modulesanywhere) 1.5.0 to below 10.0.0 - Server-Side Request Forgery and Local File Read via Module Parameter Overrides
27 september 2026
-
Modules Anywhere (modulesanywhere) 1.5.0 to below 10.0.0 - Server-Side Request Forgery and Local File Read via Module Parameter Overrides
27 september 2026
-
UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)
26 september 2026
-
UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)
26 september 2026
-
Event Gallery (com_eventgallery) below 6.5.0 - Authenticated Path Traversal Folder Deletion, CSRF Image Upload and Overwrite, Reflected XSS and Guessable Order IDs
26 september 2026
-
YouTube Gallery (com_youtubegallery) below 5.7.3 - Unauthenticated SQL Injection
26 september 2026
-
AcyMailing (com_acym) below 11.1.0 - Unauthenticated File Upload (mailbox actions, POP3 mode) and File Deletion (custom file fields) (CVE-2026-94132, CVE-2026-94131)
24 september 2026
-
EasyStore (com_easystore) below 3.0.1 - Unauthenticated Customer Address Disclosure, Authenticated SQL Injection, CSRF and ACL Bypass
23 september 2026
-
Gridbox (com_gridbox) 2.20.2.3 to 2.20.3 - Unauthenticated Time-Based SQL Injection (author parameter, fixed in 2.20.3.1)
21 september 2026
-
OS Gallery (com_osgallery) below 6.2.7 - Unauthenticated SQL Injection via Public Search Module
20 september 2026
-
OS Gallery (com_osgallery) below 6.2.7 - Authenticated, Privileged Remote Code Execution and SQL Injection (3 CVEs)
20 september 2026
-
JoomGallery (com_joomgallery) 4.0.0 to 4.4.1 - Unauthenticated Arbitrary File Upload via the TUS Endpoint (CVE-2026-84048)
15 september 2026
-
J2Store / J2Commerce (com_j2store) 4.1.7 (Joomla 5 / 6 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
15 september 2026
-
J2Store / J2Commerce (com_j2store) 4.0.22 (Joomla 4 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
15 september 2026
-
J2Store / J2Commerce (com_j2store) 3.3.22 (Joomla 3 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
15 september 2026
-
SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 8.6), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1
14 september 2026
-
Snippets (snippets) 1.0.0 to below 7.0.0 - Authenticated Stored XSS via Snippet Variable Overrides
13 september 2026
-
Snippets (snippets) 1.0.0 to below 7.0.0 - Authenticated Stored XSS via Snippet Variable Overrides
13 september 2026
-
Snippets (snippets) 1.0.0 to below 7.0.0 - Authenticated Stored XSS via Snippet Variable Overrides
13 september 2026
-
Snippets (snippets) 1.0.0 to below 7.0.0 - Authenticated Stored XSS via Snippet Variable Overrides
13 september 2026
-
Snippets (snippets) 1.0.0 to below 7.0.0 - Authenticated Stored XSS via Snippet Variable Overrides
13 september 2026
-
Tabs & Accordions (tabsaccordions) 3.0.0 to below 3.1.0 - Authenticated Stored XSS via Crafted data-rlta-alias Attributes
13 september 2026
-
Tabs & Accordions (tabsaccordions) 3.0.0 to below 3.1.0 - Authenticated Stored XSS via Crafted data-rlta-alias Attributes
13 september 2026
Laatst geüpdatet plugins
-
Mollie API 1.2.2
09 oktober 2026
-
Payment Gateway of Stripe for WooCommerce 5.1.1
09 oktober 2026
-
Setary — Bulk Edit WordPress & WooCommerce 1.14.16
09 oktober 2026
-
Yotpo Product Reviews 1.8.4
09 oktober 2026
-
Quiz Maker by AYS 6.7.1.90
09 oktober 2026
-
Geo Controller 9.0.2
09 oktober 2026
-
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory 2.8.191
09 oktober 2026
-
Media Hygiene: Remove or Delete Unused Images and More! 6.1.0
09 oktober 2026
-
ResponsiveVoice Text To Speech 2.3.0
09 oktober 2026
-
PI Conditional cart fee / Extra charge rule for WooCommerce 1.1.70
09 oktober 2026
-
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 4.4.10
09 oktober 2026
-
HUSKY – Products Filter for WooCommerce Professional 1.4.5
09 oktober 2026
-
Bulk Page Generator – LPagery 3.1.0
09 oktober 2026
-
Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA 3.1.15
09 oktober 2026
-
10Web Booster – Website speed optimization, Cache & Page Speed optimizer 2.34.10
09 oktober 2026
-
WP Booking System – Booking Calendar 2.1.0.2
09 oktober 2026
-
BundleBoss – Product Bundles, Mix and Match & Build a Box for WooCommerce 6.2.0
09 oktober 2026
-
Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates 4.11.111
09 oktober 2026
-
VikAppointments Employees Filter 1.5.8
09 oktober 2026
-
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF 6.6.0
09 oktober 2026
-
GSheetConnector – Forminator Google Sheets Connector, Export Forminator Submissions 2.0.1
09 oktober 2026
-
Pinterest for WooCommerce 1.5.3
09 oktober 2026
-
WC Search Orders By Product 4.0
09 oktober 2026
-
WP Customer Area 8.3.7
09 oktober 2026
-
WC Moneris Payment Gateway 3.8.1
09 oktober 2026
-
Gutenverse – WordPress Blocks, Page Builder & Site Editor 4.0.12
09 oktober 2026
-
Gutenverse Form – Contact Form Builder, Block Form & Booking Form 3.0.12
09 oktober 2026
-
Website Toolbox Forum 2.2.1
09 oktober 2026
-
Smaily Connect 3.17.1
09 oktober 2026
-
Widget Context 1.5.0
09 oktober 2026
-
GSheetConnector – Elementor Forms Google Sheet Connector to Sync Submissions to Google Sheets 1.3.7
09 oktober 2026
-
SNY Auto Featured Image 2.1.1
09 oktober 2026
-
Spectra Legacy – Gutenberg Blocks 2.20.5
09 oktober 2026
-
WP STAGING – Backups & Restore, Migration & Clone Plugin – Cloud Backups, Scheduled Backups 4.17.0
09 oktober 2026
-
Pay for Payment for WooCommerce – Payment Gateway Fees & Discounts 3.0.1
09 oktober 2026
-
Ultimate Maps by Supsystic 1.6.2
09 oktober 2026
-
Easy Google Maps 1.15.2
09 oktober 2026
-
Data Tables Generator by Supsystic 1.15.4
09 oktober 2026
-
Photo Gallery – Responsive Image Galleries by Supsystic 1.21.2
09 oktober 2026
-
Pricing Table by Supsystic 1.12.1
09 oktober 2026
-
Webheadcoder Multi-Step Forms for Contact Form 7 4.7.1
09 oktober 2026
-
Smart Popup by Supsystic 1.13.3
09 oktober 2026
-
WSP MCP – Free MCP Plugin for WordPress: Connect Claude, ChatGPT & AI Agents 2.9.5
09 oktober 2026
-
Copy Anything to Clipboard for WordPress – Copy Button, Copy Text & Copy Code 5.5.4
09 oktober 2026
-
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars 4.1.1
09 oktober 2026
-
Wallet for WooCommerce 1.7.3
09 oktober 2026
-
Autolanguage PRO plugin 2.7.1
09 oktober 2026
-
WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings 5.0.2
09 oktober 2026
-
annasta Filters for WooCommerce 1.8.5
09 oktober 2026
-
YOOtheme Elements PRO for Joomla 2.4.0
09 oktober 2026


