Known Vulnerabilities for UP Plugin For Joomla by Lomart.fr
Listed below are 10 of the newest known vulnerabilities associated with "UP Plugin For Joomla" by "Lomart.fr".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-97163 json | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-97162 json | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-97161 json | Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-97160 json | Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-85195 json | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-85190 json | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Qui... | Not Provided | 2026-09-14 | 2026-09-15 |
| CVE-2026-79701 json | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder ... | Not Provided | 2026-09-14 | 2026-09-15 |
| CVE-2026-78375 json | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and... | Not Provided | 2026-09-14 | 2026-09-15 |
| CVE-2026-78374 json | Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78070 json | Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving a... | Not Provided | 2026-08-28 | 2026-08-28 |