VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2023-23754
[20230501] - Core - Open Redirect and XSS within the mfa select
Published 2023-05-30 · Modified
6.1EPSS 0.004
CVE-2022-27913
[20221002] - Core - RXSS through reflection of user input in headings
Published 2022-10-25 · Modified
6.1EPSS 0.004
CVE-2024-40743
[20240805] - Core - XSS vectors in Outputfilter::strip* methods
Published 2024-08-20 · Analyzed
6.1EPSS 0.003
CVE-2024-27186
[20240803] - Core - XSS in HTML Mail Templates
Published 2024-08-20 · Analyzed
6.1EPSS 0.003
CVE-2024-27184
[20240801] - Core - Inadequate validation of internal URLs
Published 2024-08-20 · Analyzed
6.1EPSS 0.003
CVE-2024-40747
[20250101] - Core - XSS vectors in module chromes
Published 2025-01-07 · Analyzed
6.1EPSS 0.003
CVE-2026-48951
Joomla! Core - [20260705] - XSS in various modalreturn layouts
Published 2026-07-07 · Analyzed
6.1EPSS 0.002
CVE-2026-48950
Joomla! Core - [20260704] - XSS in com_templates
Published 2026-07-07 · Analyzed
6.1EPSS 0.002
CVE-2026-48949
Joomla! Core - [20260703] - XSS in MFA method management
Published 2026-07-07 · Analyzed
6.1EPSS 0.002
CVE-2026-48952
Joomla! Core - [20260706] - XSS in com_installer
Published 2026-07-07 · Analyzed
6.1EPSS 0.002
CVE-2026-48954
Joomla! Core - [20260708] - XSS through language overrides
Published 2026-07-07 · Undergoing Analysis
6.1EPSS 0.002
CVE-2026-48953
Joomla! Core - [20260707] - XSS in the generic image output layout
Published 2026-07-07 · Analyzed
6.1EPSS 0.002
CVE-2025-63082
Joomla! Core - [20260101] - Inadequate content filtering for data URLs
Published 2026-01-06 · Analyzed
6.1EPSS 0.002
CVE-2025-63083
Joomla! Core - [20260102] - XSS vector in the pagebreak plugin
Published 2026-01-06 · Analyzed
6.1EPSS 0.002
CVE-2011-5004
Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
Published 2011-12-25 · Modified
6.0EPSS 0.016
CVE-2011-5134
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information.
Published 2012-08-30 · Modified
6.0EPSS 0.011
CVE-2012-2902
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero, allows remote authors to execute arbitrary PHP code by uploading a PHP file with a double extension as demonstrated by .jpg.pht.
Published 2012-05-21 · Modified
6.0EPSS 0.010
CVE-2010-5044
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. NOTE: some of these details are obtained from third party information.
Published 2011-11-02 · Modified
6.02 PoCEPSS 0.010
CVE-2010-4838
SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.
Published 2011-09-13 · Modified
6.01 PoCEPSS 0.008
CVE-2010-5043
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.
Published 2011-11-02 · Modified
6.01 PoCEPSS 0.008
CVE-2018-11324
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.
Published 2018-05-22 · Modified
5.9EPSS 0.013
CVE-2026-21631
Joomla! Core - [20260303] - XSS vector in com_associations comparison view
Published 2026-04-01 · Analyzed
5.9EPSS 0.002
CVE-2026-21632
Joomla! Core - [20260304] - XSS vectors in various article title outputs
Published 2026-04-01 · Analyzed
5.9EPSS 0.002
CVE-2010-0467
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
Published 2010-02-02 · Modified
5.82 PoCEPSS 0.433
CVE-2013-3242
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors.
Published 2013-05-03 · Modified
5.51 PoCEPSS 0.048
CVE-2009-3945
Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.
Published 2009-11-16 · Modified
5.5EPSS 0.011
CVE-2021-26028
[20210308] - Core - Path Traversal within joomla/archive zip class
Published 2021-03-04 · Modified
5.5EPSS 0.010
CVE-2018-15880
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.
Published 2018-08-29 · Modified
5.4EPSS 0.010
CVE-2011-3595
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
Published 2020-01-22 · Modified
5.4EPSS 0.008
CVE-2019-6262
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.
Published 2019-01-16 · Modified
5.4EPSS 0.006
CVE-2024-21730
[20240702] - Core - Self-XSS in fancyselect list field layout
Published 2024-07-09 · Modified
5.4EPSS 0.004
CVE-2026-72531
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
5.4EPSS 0.003
CVE-2026-72532
Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
5.4EPSS 0.003
CVE-2026-71572
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
Published 2023-02-16 · Analyzed
5.3KEV1 PoCEPSS 0.998
CVE-2020-11890
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
Published 2020-04-21 · Modified
5.3EPSS 0.028
CVE-2005-4650
Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.
Published 2006-01-14 · Modified
5.3EPSS 0.016
CVE-2020-15698
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
Published 2020-07-15 · Modified
5.3EPSS 0.014
CVE-2020-10240
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
Published 2020-03-16 · Modified
5.3EPSS 0.013
CVE-2021-23123
[20210101] - Core - com_modules exposes module names
Published 2021-01-12 · Modified
5.3EPSS 0.012
← Prev12 / 17Next →