VendorsJoomla!joomla%5C!all versions
Vulnerabilities

Joomla! Joomla!

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

653CVEs
CVE-2026-40384
Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint
Published 2026-05-26 · Analyzed
7.5EPSS 0.005
CVE-2024-40748
[20250102] - Core - XSS vector in the id attribute of menu lists
Published 2025-01-07 · Analyzed
7.5EPSS 0.004
CVE-2026-48901
Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects
Published 2026-05-26 · Analyzed
7.5EPSS 0.004
CVE-2025-25227
[20250402] - Joomla Core - MFA Authentication Bypass
Published 2025-04-08 · Analyzed
7.5EPSS 0.004
CVE-2024-40749
[20250103] - Core - Read ACL violation in multiple core views
Published 2025-01-07 · Analyzed
7.5EPSS 0.004
CVE-2024-27187
[20240804] - Core - Improper ACL for backend profile view
Published 2024-08-20 · Analyzed
7.5EPSS 0.004
CVE-2026-21629
Joomla! Core - [20260301] - ACL hardening in com_ajax
Published 2026-04-01 · Analyzed
7.3EPSS 0.002
CVE-2018-17856
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
Published 2018-10-09 · Modified
7.2EPSS 0.027
CVE-2026-25900
Joomla! Core - [20260501] - XSS in feed modules
Published 2026-05-26 · Analyzed
6.9EPSS 0.002
CVE-2026-30894
Joomla! Core - [20260503] - XSS in com_contenthistory
Published 2026-05-26 · Analyzed
6.9EPSS 0.002
CVE-2026-48903
Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.
Published 2026-05-26 · Analyzed
6.9EPSS 0.002
CVE-2026-25901
Joomla! Core - [20260502] - XSS in com_associations
Published 2026-05-26 · Analyzed
6.9EPSS 0.002
CVE-2026-30895
Joomla! Core - [20260504] - XSS in readmore links
Published 2026-05-26 · Analyzed
6.9EPSS 0.002
CVE-2026-48905
Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.
Published 2026-05-26 · Analyzed
6.9EPSS 0.002
CVE-2013-5576
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
Published 2013-10-09 · Modified
6.81 PoCEPSS 0.482
CVE-2006-5048
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php, (2) lang.php, (3) client.php, and (4) server.php.
Published 2006-09-27 · Modified
6.81 PoCEPSS 0.158
CVE-2010-2122
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-06-01 · Modified
6.82 PoCEPSS 0.117
CVE-2010-1056
Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-03-23 · Modified
6.81 PoCEPSS 0.114
CVE-2010-1979
Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-19 · Modified
6.81 PoCEPSS 0.112
CVE-2010-1476
Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.
Published 2010-04-19 · Modified
6.81 PoCEPSS 0.099
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-19 · Modified
6.81 PoCEPSS 0.095
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-19 · Modified
6.81 PoCEPSS 0.095
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-04 · Modified
6.81 PoCEPSS 0.095
CVE-2010-1718
Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-04 · Modified
6.81 PoCEPSS 0.095
CVE-2010-2507
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-06-28 · Modified
6.81 PoCEPSS 0.094
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-04 · Modified
6.81 PoCEPSS 0.094
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.
Published 2010-12-29 · Modified
6.81 PoCEPSS 0.085
CVE-2010-1723
Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-05-04 · Modified
6.81 PoCEPSS 0.084
CVE-2010-1607
Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-29 · Modified
6.81 PoCEPSS 0.082
CVE-2010-1715
Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-05-04 · Modified
6.81 PoCEPSS 0.082
CVE-2010-1469
Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-19 · Modified
6.81 PoCEPSS 0.082
CVE-2010-1473
Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-19 · Modified
6.81 PoCEPSS 0.082
CVE-2010-1478
Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Published 2010-04-19 · Modified
6.81 PoCEPSS 0.082
CVE-2010-2920
Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
Published 2010-07-30 · Modified
6.81 PoCEPSS 0.057
CVE-2010-2129
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.
Published 2010-06-01 · Modified
6.81 PoCEPSS 0.050
CVE-2010-2680
Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php.
Published 2010-07-09 · Modified
6.81 PoCEPSS 0.048
CVE-2011-5148
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.
Published 2012-08-31 · Modified
6.81 PoCEPSS 0.048
CVE-2006-5043
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload.php, a variant of CVE-2006-3528.
Published 2006-09-27 · Modified
6.81 PoCEPSS 0.040
CVE-2006-4468
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.
Published 2006-08-31 · Modified
6.8EPSS 0.020
CVE-2010-0760
Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) file parameter to libraries/jquery/js/ui/jsloader.php and the (2) files[] parameter to libraries/jquery/js/jsloader.php, a different vector than CVE-2010-0759. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2010-02-27 · Modified
6.81 PoCEPSS 0.019
← Prev9 / 17Next →