Known Vulnerabilities for Session by Joomla
Listed below are 1 of the newest known vulnerabilities associated with "Session" by "Joomla".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103651 json | MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103590 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103589 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103588 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Tran... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103587 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Boo... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103544 json | A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown func... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103475 json | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in it... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103389 json | MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103388 json | MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALI... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103321 json | MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview ima... | Not Provided | 2026-09-30 | 2026-09-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Joomla | Session | 1.3.0 |