VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2010-5286
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2012-11-26 · Modified
10.01 PoCEPSS 0.121
CVE-2012-6503
Unspecified vulnerability in the NinjaXplorer component before 1.0.7 for Joomla! has unknown impact and attack vectors.
Published 2013-01-24 · Modified
10.0EPSS 0.017
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
Published 2017-05-17 · Modified
9.82 PoCEPSS 0.998
CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Published 2016-12-30 · Analyzed
9.8KEV9 PoCEPSS 0.997
CVE-2016-10045
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
Published 2016-12-30 · Modified
9.83 PoCEPSS 0.977
CVE-2016-8869
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
Published 2016-11-04 · Modified
9.81 PoCEPSS 0.973
CVE-2019-10945
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.
Published 2019-04-10 · Modified
9.81 PoCEPSS 0.380
CVE-2020-35613
[20201104] - Core - SQL injection in com_users list view
Published 2020-12-28 · Modified
9.8EPSS 0.289
CVE-2019-12765
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
Published 2019-06-11 · Modified
9.81 PoCEPSS 0.105
CVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
Published 2017-09-20 · Modified
9.8EPSS 0.069
CVE-2019-11831
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
Published 2019-05-09 · Modified
9.8EPSS 0.054
CVE-2017-16634
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
Published 2017-11-09 · Modified
9.8EPSS 0.044
CVE-2018-6376
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
Published 2018-01-30 · Modified
9.8EPSS 0.041
CVE-2018-11325
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
Published 2018-05-22 · Modified
9.8EPSS 0.033
CVE-2018-15882
An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.
Published 2018-08-29 · Modified
9.8EPSS 0.029
CVE-2019-7743
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
Published 2019-02-12 · Modified
9.8EPSS 0.027
CVE-2016-9081
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
Published 2017-01-23 · Modified
9.8EPSS 0.021
CVE-2016-9836
The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types.
Published 2016-12-05 · Modified
9.8EPSS 0.019
CVE-2020-10243
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.
Published 2020-03-16 · Modified
9.8EPSS 0.018
CVE-2019-19846
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
Published 2019-12-18 · Modified
9.8EPSS 0.017
CVE-2022-23799
[20220307] - Core - Variable Tampering on JInput $_REQUEST data
Published 2022-03-30 · Modified
9.8EPSS 0.012
CVE-2022-23795
[20220303] - Core - User row are not bound to a authentication mechanism
Published 2022-03-30 · Modified
9.8EPSS 0.011
CVE-2010-1433
Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
Published 2021-06-21 · Modified
9.8EPSS 0.011
CVE-2022-23797
[20220305] - Core - Inadequate filtering on the selected Ids
Published 2022-03-30 · Modified
9.8EPSS 0.011
CVE-2010-1435
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
Published 2021-06-21 · Modified
9.8EPSS 0.011
CVE-2026-73373
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
9.8EPSS 0.006
CVE-2026-40383
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Published 2026-05-26 · Analyzed
9.8EPSS 0.006
CVE-2026-48904
Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints
Published 2026-05-26 · Analyzed
9.8EPSS 0.005
CVE-2026-35223
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
Published 2026-05-26 · Analyzed
9.8EPSS 0.005
CVE-2026-48898
Joomla! Core - [20260513] - Privilege escalation through com_users batch task
Published 2026-05-26 · Analyzed
9.8EPSS 0.005
CVE-2025-25226
[20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database package
Published 2025-04-08 · Analyzed
9.8EPSS 0.005
CVE-2026-35222
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
Published 2026-05-26 · Analyzed
9.8EPSS 0.005
CVE-2026-35221
Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder
Published 2026-05-26 · Analyzed
9.8EPSS 0.005
CVE-2026-48899
Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
Published 2026-05-26 · Analyzed
9.8EPSS 0.004
CVE-2026-48902
Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links
Published 2026-05-26 · Modified
9.8EPSS 0.003
CVE-2007-4188
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
Published 2007-08-08 · Modified
9.3EPSS 0.038
CVE-2008-1465
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than CVE-2008-0562.
Published 2008-03-24 · Modified
9.31 PoCEPSS 0.014
CVE-2011-1151
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
Published 2020-02-05 · Modified
9.1EPSS 0.019
CVE-2021-23128
[20210302] - Core - Potential Insecure FOFEncryptRandval
Published 2021-03-04 · Modified
9.1EPSS 0.014
CVE-2021-23127
[20210301] - Core - Insecure randomness within 2FA secret generation
Published 2021-03-04 · Modified
9.1EPSS 0.014
1 / 17Next →