Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-72531 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | ||
| CVE-2026-71572 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. | ||
| CVE-2026-72532 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. | ||
| CVE-2024-21730 | Med | 0.35 | 5.4 | 0.00 | Jul 9, 2024 | The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. | ||
| CVE-2022-23794 | Med | 0.35 | 5.3 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application. | ||
| CVE-2021-26037 | Med | 0.35 | 5.3 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked. | ||
| CVE-2021-26031 | Med | 0.35 | 5.3 | 0.01 | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI. | ||
| CVE-2021-26029 | Med | 0.35 | 5.3 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field. | ||
| CVE-2021-26027 | Med | 0.35 | 5.3 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. | ||
| CVE-2021-23126 | Med | 0.35 | 5.3 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret. | ||
| CVE-2021-23123 | Med | 0.35 | 5.3 | 0.01 | Jan 12, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules. | ||
| CVE-2020-35614 | Med | 0.35 | 5.3 | 0.01 | Dec 28, 2020 | An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page. | ||
| CVE-2020-15699 | Med | 0.35 | 5.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. | ||
| CVE-2020-15698 | Med | 0.35 | 5.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials | ||
| CVE-2020-11891 | Med | 0.35 | 5.3 | 0.01 | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups. | ||
| CVE-2020-11890 | Med | 0.35 | 5.3 | 0.03 | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. | ||
| CVE-2020-11889 | Med | 0.35 | 5.3 | 0.01 | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups. | ||
| CVE-2020-10240 | Med | 0.35 | 5.3 | 0.01 | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses. | ||
| CVE-2011-4912 | Med | 0.35 | 5.3 | 0.01 | Feb 4, 2020 | Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. | ||
| CVE-2011-3595 | Med | 0.35 | 5.4 | 0.01 | Jan 22, 2020 | Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. |
- risk 0.35cvss 5.4epss 0.00
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
- risk 0.35cvss 5.4epss 0.00
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
- risk 0.35cvss 5.4epss 0.00
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
- risk 0.35cvss 5.4epss 0.00
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
- risk 0.35cvss 5.3epss 0.03
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
- risk 0.35cvss 5.3epss 0.01
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
- risk 0.35cvss 5.4epss 0.01
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
Page 10 of 21