VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2010-2515
Multiple SQL injection vulnerabilities in index.php in the JFaq (com_jfaq) component 1.2 for Joomla!, when magic_quotes_gpc is disabled, allow (1) remote attackers to execute arbitrary SQL commands via the id parameter, and (2) remote authenticated users with "Public Front-end" permissions to execute arbitrary SQL commands via the titlu parameter (title field). NOTE: some of these details are obtained from third party information.
Published 2010-06-28 · Modified
6.8EPSS 0.017
CVE-2010-1950
SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2010-05-18 · Modified
6.81 PoCEPSS 0.016
CVE-2015-5397
Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.
Published 2015-07-14 · Modified
6.8EPSS 0.014
CVE-2009-4946
Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter in a messages action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2010-07-22 · Modified
6.8EPSS 0.012
CVE-2009-4059
SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a thumbs action to index.php.
Published 2009-11-24 · Modified
6.81 PoCEPSS 0.010
CVE-2010-4517
SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the char parameter in an item action to index.php.
Published 2010-12-09 · Modified
6.81 PoCEPSS 0.010
CVE-2010-4638
SQL injection vulnerability in the submitSurvey function in controller.php in JQuarks4s (com_jquarks4s) component 1.0.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the q parameter in a submitSurvey action to index.php.
Published 2010-12-30 · Modified
6.81 PoCEPSS 0.009
CVE-2008-1559
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
Published 2008-03-31 · Modified
6.82 PoCEPSS 0.009
CVE-2009-4199
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.
Published 2009-12-04 · Modified
6.81 PoCEPSS 0.008
CVE-2015-8563
Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2015-12-16 · Modified
6.8EPSS 0.008
CVE-2020-15700
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
Published 2020-07-15 · Modified
6.8EPSS 0.005
CVE-2020-15695
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
Published 2020-07-15 · Modified
6.8EPSS 0.005
CVE-2020-35615
[20201106] - Core - CSRF in com_privacy emailexport feature
Published 2020-12-28 · Modified
6.8EPSS 0.004
CVE-2024-21726
[20240205] - Core - Inadequate content filtering within the filter code
Published 2024-02-20 · Analyzed
6.5EPSS 0.488
CVE-2006-4471
The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.
Published 2006-08-31 · Modified
6.5EPSS 0.024
CVE-2018-11321
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
Published 2018-05-22 · Modified
6.5EPSS 0.020
CVE-2019-12764
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
Published 2019-06-11 · Modified
6.5EPSS 0.011
CVE-2017-7989
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
Published 2017-04-25 · Modified
6.5EPSS 0.010
CVE-2008-6276
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.
Published 2009-02-25 · Modified
6.5EPSS 0.009
CVE-2021-26034
[20210503] - Core - CSRF in data download endpoints
Published 2021-05-26 · Modified
6.5EPSS 0.005
CVE-2021-26033
[20210502] - Core - CSRF in AJAX reordering endpoint
Published 2021-05-26 · Modified
6.5EPSS 0.005
CVE-2026-48955
Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
Published 2026-07-07 · Analyzed
6.5EPSS 0.003
CVE-2026-48947
Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints
Published 2026-07-07 · Analyzed
6.4EPSS 0.003
CVE-2026-48956
Joomla! Core - [20260710] - Incorrect Access Control in com_modules
Published 2026-07-07 · Analyzed
6.4EPSS 0.003
CVE-2026-73336
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
6.4EPSS 0.003
CVE-2026-48900
Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler
Published 2026-05-26 · Analyzed
6.4EPSS 0.003
CVE-2024-21722
[20240201] - Core - Insufficient session expiration in MFA management views
Published 2024-02-20 · Analyzed
6.3EPSS 0.005
CVE-2023-23750
[20230101] - Core - CSRF within post-installation messages
Published 2023-02-01 · Modified
6.3EPSS 0.002
CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Published 2019-04-19 · Modified
6.11 PoCEPSS 0.872
CVE-2021-26030
[20210401] - Core - Escape xss in logo parameter error pages
Published 2021-04-14 · Modified
6.1EPSS 0.823
CVE-2021-23124
[20210102] - Core - XSS in mod_breadcrumbs aria-label attribute
Published 2021-01-12 · Modified
6.1EPSS 0.790
CVE-2018-6377
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
Published 2018-01-30 · Modified
6.1EPSS 0.565
CVE-2024-21725
[20240204] - Core - XSS in mail address outputs
Published 2024-02-20 · Analyzed
6.1EPSS 0.322
CVE-2020-15696
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
Published 2020-07-15 · Modified
6.1EPSS 0.028
CVE-2017-9934
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
Published 2017-07-17 · Modified
6.1EPSS 0.022
CVE-2018-6379
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
Published 2018-01-30 · Modified
6.1EPSS 0.017
CVE-2018-6380
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
Published 2018-01-30 · Modified
6.1EPSS 0.017
CVE-2018-12711
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.
Published 2018-06-26 · Modified
6.1EPSS 0.014
CVE-2018-6378
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
Published 2018-05-22 · Modified
6.1EPSS 0.014
CVE-2017-7985
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
Published 2017-04-25 · Modified
6.1EPSS 0.013
← Prev10 / 17Next →