CVE-2026-40383
joomla: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-40383)
Affected
- bitnami/joomla
3.2.1..* - bitnami/joomla
6.0.0..*
Description
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Source: BSI
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
3.0.03.2.14.0.04.1.06.0.0Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
References & sources
- https://developer.joomla.org/security-centre/1044-20260512-core-mfa-authentication-bypass.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-48897web
- https://developer.joomla.org/security-centre/1039-20260507-core-authenticated-blind-sqli-in-com-tags.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-35222web
- https://developer.joomla.org/security-centre/1041-20260509-core-lfi-in-htmlview-layout-parameter.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-40383web
- https://developer.joomla.org/security-centre/1038-20260506-core-authenticated-blind-sqli-in-com-finder.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-35221web
- https://developer.joomla.org/security-centre/1042-20260510-core-path-traversal-in-com-media-webservice-endpoint.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-40384web
- https://developer.joomla.org/security-centre/1045-20260513-core-privilege-escalation-through-com-users-batch-task.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-48898web
- https://developer.joomla.org/security-centre/1034-20260502-core-xss-in-com-associations.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-25901web
- https://developer.joomla.org/security-centre/1047-20260515-core-incorrect-access-control-in-sample-data-plugins.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-48899web
- https://developer.joomla.org/security-centre/1033-20260501-core-xss-in-feed-modules.htmleuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-25900web
- https://developer.joomla.org/security-centre/1036-20260504-core-xss-in-readmore-linkseuvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-30895web
Linked CVEs
- CVE-2026-48905
Lack of input filtering leads to an XSS vector in the HTML filter code.
mediumCVSSv3 6.1 - CVE-2026-48904
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
criticalCVSSv3 9.8 - CVE-2026-48903
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
mediumCVSSv3 6.1 - CVE-2026-48902
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
criticalCVSSv3 9.8 - CVE-2026-48901
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
highCVSSv3 7.5 - CVE-2026-48900
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
mediumCVSSv3 4.3 - CVE-2026-48899
An improper access check allows privilege escalation through the com_users batch task.
criticalCVSSv3 9.8 - CVE-2026-48898
An improper access check allows privilege escalation through the com_users batch task.
criticalCVSSv3 9.8 - CVE-2026-48897
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
highCVSSv3 7.5 - CVE-2026-48896
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
highCVSSv3 7.5 - CVE-2026-40384
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
highCVSSv3 7.5 - CVE-2026-40383
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
criticalCVSSv3 9.8 - CVE-2026-35223
An improper access check allows unauthorized access to com_config webservice endpoints.
criticalCVSSv3 9.8 - CVE-2026-35222
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
criticalCVSSv3 9.8 - CVE-2026-35221
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
criticalCVSSv3 9.8 - CVE-2026-35220
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
mediumCVSSv3 4.3 - CVE-2026-30895
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
mediumCVSSv3 6.1 - CVE-2026-30894
Lack of output escaping leads to a XSS vector in the content history component.
mediumCVSSv3 6.1 - CVE-2026-25901
Lack of output escaping leads to a XSS vector in the multilingual associations component.
mediumCVSSv3 6.1 - CVE-2026-25900
Lack of output escaping leads to a XSS vector in the feed modules.
mediumCVSSv3 6.1