VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2021-26040
[20210801] - Core - Insufficient access control for com_media deletion endpoint
Published 2021-08-24 · Modified
9.1EPSS 0.009
CVE-2024-27185
[20240802] - Core - Cache Poisoning in Pagination
Published 2024-08-20 · Analyzed
9.1EPSS 0.004
CVE-2018-8045
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
Published 2018-03-14 · Modified
8.8EPSS 0.282
CVE-2018-11323
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.
Published 2018-05-22 · Modified
8.8EPSS 0.028
CVE-2020-10239
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
Published 2020-03-16 · Modified
8.8EPSS 0.027
CVE-2019-14654
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.
Published 2019-08-05 · Modified
8.8EPSS 0.023
CVE-2018-12712
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.
Published 2018-06-26 · Modified
8.8EPSS 0.023
CVE-2017-11364
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
Published 2017-08-02 · Modified
8.8EPSS 0.022
CVE-2018-17855
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
Published 2018-10-09 · Modified
8.8EPSS 0.019
CVE-2018-17858
An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.
Published 2018-10-09 · Modified
8.8EPSS 0.010
CVE-2020-8420
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
Published 2020-01-28 · Modified
8.8EPSS 0.007
CVE-2020-10241
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
Published 2020-03-16 · Modified
8.8EPSS 0.007
CVE-2020-13760
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
Published 2020-06-02 · Modified
8.8EPSS 0.007
CVE-2026-48958
Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
Published 2026-07-07 · Analyzed
8.8EPSS 0.005
CVE-2019-18650
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
Published 2019-11-06 · Modified
8.8EPSS 0.005
CVE-2020-8419
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
Published 2020-01-28 · Modified
8.8EPSS 0.005
CVE-2026-48957
Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
Published 2026-07-07 · Analyzed
8.8EPSS 0.004
CVE-2026-48948
Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
Published 2026-07-07 · Analyzed
8.8EPSS 0.004
CVE-2026-23899
Joomla! Core - [20260306] - Improper access check in webservice endpoints
Published 2026-04-01 · Analyzed
8.8EPSS 0.004
CVE-2026-21630
Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint
Published 2026-04-01 · Analyzed
8.8EPSS 0.003
CVE-2026-23898
Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate
Published 2026-04-01 · Analyzed
8.6EPSS 0.005
CVE-2026-71574
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
8.5EPSS 0.003
CVE-2026-71573
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
8.3EPSS 0.003
CVE-2026-73337
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2
Published 2026-08-18 · Analyzed
8.2EPSS 0.005
CVE-2026-48896
Joomla! Core - [20260511] - MFA Authentication Bypass
Published 2026-05-26 · Analyzed
8.2EPSS 0.004
CVE-2026-48897
Joomla! Core - [20260512] - MFA Authentication Bypass
Published 2026-05-26 · Analyzed
8.2EPSS 0.004
CVE-2016-8870
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Published 2016-11-04 · Modified
8.11 PoCEPSS 0.811
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.
Published 2015-10-29 · Modified
7.51 PoCEPSS 1.000
CVE-2015-8562
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
Published 2015-12-16 · Modified
7.52 PoCEPSS 0.983
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.
Published 2015-10-29 · Modified
7.51 PoCEPSS 0.945
CVE-2015-7858
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.
Published 2015-10-29 · Modified
7.51 PoCEPSS 0.856
CVE-2014-7228
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and Professional 2.0.0 through 2.4.4; and CMS Update 1.0.a1 through 1.0.1, when performing a backup or update for an archive, does not delete parameters from $_GET and $_POST when it is cleansing $_REQUEST, but later accesses $_GET and $_POST using the getQueryParam function, which allows remote attackers to bypass encryption and execute arbitrary code via a command message that extracts a crafted archive.
Published 2014-11-03 · Modified
7.51 PoCEPSS 0.554
CVE-2010-1980
Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-19 · Modified
7.51 PoCEPSS 0.188
CVE-2010-1983
Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-05-19 · Modified
7.51 PoCEPSS 0.188
CVE-2010-1495
Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-23 · Modified
7.51 PoCEPSS 0.185
CVE-2010-2259
Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-06-09 · Modified
7.51 PoCEPSS 0.181
CVE-2010-1955
Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-18 · Modified
7.51 PoCEPSS 0.179
CVE-2010-1956
Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-05-18 · Modified
7.51 PoCEPSS 0.170
CVE-2010-1531
Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
Published 2010-04-26 · Modified
7.51 PoCEPSS 0.169
CVE-2010-1471
Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-19 · Modified
7.51 PoCEPSS 0.162
← Prev2 / 17Next →