VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2020-8421
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
Published 2020-01-28 · Modified
6.1EPSS 0.010
CVE-2020-10242
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
Published 2020-03-16 · Modified
6.1EPSS 0.010
CVE-2020-24599
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
Published 2020-08-26 · Modified
6.1EPSS 0.010
CVE-2020-24598
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
Published 2020-08-26 · Modified
6.1EPSS 0.010
CVE-2020-13762
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
Published 2020-06-02 · Modified
6.1EPSS 0.010
CVE-2020-13761
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
Published 2020-06-02 · Modified
6.1EPSS 0.010
CVE-2017-11612
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
Published 2017-07-26 · Modified
6.1EPSS 0.010
CVE-2019-7739
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this.
Published 2019-02-12 · Modified
6.1EPSS 0.009
CVE-2019-12766
An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.
Published 2019-06-11 · Modified
6.1EPSS 0.009
CVE-2021-26032
[20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUpload
Published 2021-05-26 · Modified
6.1EPSS 0.008
CVE-2021-23129
[20210303] - Core - XSS within alert messages showed to users
Published 2021-03-04 · Modified
6.1EPSS 0.008
CVE-2021-23130
[20210304] - Core - XSS within the feed parser library
Published 2021-03-04 · Modified
6.1EPSS 0.008
CVE-2019-7740
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
Published 2019-02-12 · Modified
6.1EPSS 0.008
CVE-2019-7741
An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
Published 2019-02-12 · Modified
6.1EPSS 0.008
CVE-2019-7744
An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.
Published 2019-02-12 · Modified
6.1EPSS 0.008
CVE-2019-11809
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.
Published 2019-05-20 · Modified
6.1EPSS 0.008
CVE-2019-7742
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.
Published 2019-02-12 · Modified
6.1EPSS 0.008
CVE-2017-7987
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
Published 2017-04-25 · Modified
6.1EPSS 0.008
CVE-2017-7984
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
Published 2017-04-25 · Modified
6.1EPSS 0.008
CVE-2017-7986
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
Published 2017-04-25 · Modified
6.1EPSS 0.008
CVE-2021-23125
[20210103] - Core - XSS in com_tags image parameters
Published 2021-01-12 · Modified
6.1EPSS 0.008
CVE-2019-6261
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.
Published 2019-01-16 · Modified
6.1EPSS 0.008
CVE-2019-6264
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.
Published 2019-01-16 · Modified
6.1EPSS 0.008
CVE-2019-9711
An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
Published 2019-03-12 · Modified
6.1EPSS 0.008
CVE-2019-9712
An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
Published 2019-03-12 · Modified
6.1EPSS 0.008
CVE-2019-9714
An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
Published 2019-03-12 · Modified
6.1EPSS 0.008
CVE-2021-26039
[20210705] - Core - XSS in com_media imagelist
Published 2021-07-07 · Modified
6.1EPSS 0.007
CVE-2021-26035
[20210701] - Core - XSS in JForm Rules field
Published 2021-07-07 · Modified
6.1EPSS 0.007
CVE-2015-5608
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
Published 2017-09-20 · Modified
6.1EPSS 0.007
CVE-2022-23800
[20220308] - Core - Inadequate content filtering within the filter code
Published 2022-03-30 · Modified
6.1EPSS 0.007
CVE-2019-16725
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Published 2019-09-24 · Modified
6.1EPSS 0.007
CVE-2022-23798
[20220306] - Core - Inadequate validation of internal URLs
Published 2022-03-30 · Modified
6.1EPSS 0.006
CVE-2022-23801
[20220309] - Core - XSS attack vector through SVG
Published 2022-03-30 · Modified
6.1EPSS 0.006
CVE-2022-23796
[20220304] - Core - Missing input validation within com_fields class inputs
Published 2022-03-30 · Modified
6.1EPSS 0.006
CVE-2024-21724
[20240203] - Core - XSS in media selection fields
Published 2024-02-20 · Modified
6.1EPSS 0.005
CVE-2022-27914
[20221101] - Core - RXSS through reflection of user input in com_media
Published 2022-11-08 · Modified
6.1EPSS 0.005
CVE-2024-26279
[20240704] - Core - XSS in Wrapper extensions
Published 2024-07-09 · Modified
6.1EPSS 0.005
CVE-2024-26278
[20240705] - Core - XSS in com_fields default field value
Published 2024-07-09 · Modified
6.1EPSS 0.004
CVE-2024-21731
[20240703] - Core - XSS in StringHelper::truncate method
Published 2024-07-09 · Modified
6.1EPSS 0.004
CVE-2024-21729
[20240701] - Core - XSS in accessible media selection field
Published 2024-07-09 · Modified
6.1EPSS 0.004
← Prev11 / 17Next →