Known Vulnerabilities for Web Frontend by Amarok
Listed below are 1 of the newest known vulnerabilities associated with "Web Frontend" by "Amarok".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63264 json | The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller. | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-62414 json | The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | Not Provided | 2026-07-20 | 2026-07-22 |
| CVE-2026-62236 json | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret f... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-60027 json | The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticat... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-60025 json | The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-59102 json | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arb... | Not Provided | 2026-07-02 | 2026-07-06 |
| CVE-2026-58652 json | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-ap... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-57334 json | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | Not Provided | 2026-06-29 | 2026-06-29 |
| CVE-2026-56237 json | Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are expose... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-55431 json | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33... | Not Provided | 2026-07-08 | 2026-07-08 |