VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2017-8057
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
Published 2017-04-25 · Modified
5.3EPSS 0.011
CVE-2017-7983
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
Published 2017-04-25 · Modified
5.3EPSS 0.011
CVE-2021-23126
[20210301] - Core - Insecure randomness within 2FA secret generation
Published 2021-03-04 · Modified
5.3EPSS 0.011
CVE-2019-19845
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
Published 2019-12-18 · Modified
5.3EPSS 0.011
CVE-2019-18674
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.
Published 2019-11-06 · Modified
5.3EPSS 0.011
CVE-2020-35614
[20201105] - Core - User Enumeration in backend login
Published 2020-12-28 · Modified
5.3EPSS 0.011
CVE-2021-26031
[20210402] - Core - Inadequate filters on module layout settings
Published 2021-04-14 · Modified
5.3EPSS 0.010
CVE-2021-26029
[20210309] - Core - Inadequate filtering of form contents could allow to overwrite the author field
Published 2021-03-04 · Modified
5.3EPSS 0.010
CVE-2017-7988
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
Published 2017-04-25 · Modified
5.3EPSS 0.010
CVE-2019-15028
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
Published 2019-08-14 · Modified
5.3EPSS 0.010
CVE-2021-26027
[20210307] - Core - ACL violation within com_content frontend editing
Published 2021-03-04 · Modified
5.3EPSS 0.010
CVE-2022-23794
[20220302] - Core - Path Disclosure within filesystem error messages
Published 2022-03-30 · Modified
5.3EPSS 0.009
CVE-2011-4907
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
Published 2020-01-15 · Modified
5.3EPSS 0.009
CVE-2021-26037
[20210703] - Core - Lack of enforced session termination
Published 2021-07-07 · Modified
5.3EPSS 0.009
CVE-2020-11891
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
Published 2020-04-21 · Modified
5.3EPSS 0.008
CVE-2011-4912
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
Published 2020-02-04 · Modified
5.3EPSS 0.008
CVE-2020-11889
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
Published 2020-04-21 · Modified
5.3EPSS 0.008
CVE-2022-27911
[20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check'
Published 2022-08-31 · Modified
5.3EPSS 0.006
CVE-2020-15699
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
Published 2020-07-15 · Modified
5.3EPSS 0.006
CVE-2022-27912
[20221001] - Core - Debug Mode leaks full request payloads including passwords
Published 2022-10-25 · Modified
5.3EPSS 0.005
CVE-2026-73371
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
5.1EPSS 0.003
CVE-2026-73372
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
5.1EPSS 0.003
CVE-2011-4804
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2011-12-14 · Modified
5.01 PoCEPSS 0.210
CVE-2010-1305
Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-08 · Modified
5.01 PoCEPSS 0.207
CVE-2010-1353
Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
Published 2010-04-12 · Modified
5.01 PoCEPSS 0.187
CVE-2010-1714
Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-04 · Modified
5.01 PoCEPSS 0.187
CVE-2010-1345
Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-09 · Modified
5.02 PoCEPSS 0.169
CVE-2010-1494
Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-23 · Modified
5.01 PoCEPSS 0.167
CVE-2008-4764
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
Published 2008-10-28 · Modified
5.01 PoCEPSS 0.165
CVE-2010-1532
Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-26 · Modified
5.01 PoCEPSS 0.163
CVE-2010-0943
Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.
Published 2010-03-08 · Modified
5.01 PoCEPSS 0.159
CVE-2010-1354
Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-04-12 · Modified
5.01 PoCEPSS 0.159
CVE-2010-1314
Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-04-08 · Modified
5.01 PoCEPSS 0.159
CVE-2010-1601
Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
Published 2010-04-29 · Modified
5.01 PoCEPSS 0.156
CVE-2010-1081
Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-03-23 · Modified
5.01 PoCEPSS 0.146
CVE-2010-0944
Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-03-08 · Modified
5.01 PoCEPSS 0.140
CVE-2010-1304
Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-08 · Modified
5.01 PoCEPSS 0.140
CVE-2010-1308
Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-08 · Modified
5.01 PoCEPSS 0.140
CVE-2010-1659
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-30 · Modified
5.01 PoCEPSS 0.140
CVE-2010-1534
Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-26 · Modified
5.01 PoCEPSS 0.136
← Prev13 / 17Next →