Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
We have discovered 4,501 live websites that are affected by CVE-2026-71572.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 4,501 live websites (3.37% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 110 versions ( 85% of all versions) |
| 636 websites | |
| 1,033 websites | |
| 387 websites | |
| 323 websites | |
| 304 websites | |
| 209 websites | |
| 208 websites | |
| 145 websites | |
| 127 websites | |
| 125 websites |
| .com | 927 websites |
| .de | 847 websites |
| .ru | 258 websites |
| .it | 225 websites |
| .fr | 212 websites |
| .org | 211 websites |
| .nl | 185 websites |
| .ch | 181 websites |
| .at | 127 websites |
| .net | 119 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.fr | **,*** | ||
| ************.ru | **,*** | ||
| ******.**.il | **,*** | ||
| **.******.org | **,*** | ||
| *********************.com | ***,*** | ||
| *****************.***.pl | ***,*** | ||
| **************.com | ***,*** | ||
| ******.net | ***,*** | ||
| ***************.************.de | ***,*** | ||
| *****************.eu | ***,*** |
FAQ