VYPR

Joomla!

by Joomla

Source repositories

CVEs (418)

  • CVE-2011-4907MedJan 15, 2020
    risk 0.35cvss 5.3epss 0.01

    Joomla! 1.5x through 1.5.12: Missing JEXEC Check

  • CVE-2019-19845MedDec 18, 2019
    risk 0.35cvss 5.3epss 0.01

    In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.

  • CVE-2019-15028MedAug 14, 2019
    risk 0.35cvss 5.3epss 0.01

    In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.

  • CVE-2019-6262MedJan 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.

  • CVE-2017-8057MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.

  • CVE-2017-7988MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.

  • CVE-2017-7983MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.

  • CVE-2005-4650MedDec 31, 2005
    risk 0.35cvss 5.3epss 0.02

    Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.

  • CVE-2025-54477MedSep 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.

  • CVE-2022-27912MedOct 25, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.

  • CVE-2022-27911MedAug 31, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.

  • CVE-2019-6263MedJan 16, 2019
    risk 0.34cvss 4.8epss 0.05

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.

  • CVE-2024-40747MedJan 7, 2025
    risk 0.33cvss 6.1epss 0.00

    Various module chromes didn't properly process inputs, leading to XSS vectors.

  • CVE-2018-11328MedMay 22, 2018
    risk 0.31cvss 4.7epss 0.02

    An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS…

  • CVE-2018-11326MedMay 22, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.

  • CVE-2021-26028MedMar 4, 2021
    risk 0.29cvss 5.5epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.

  • CVE-2026-73372MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

  • CVE-2026-73371MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

  • CVE-2026-48900MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

  • CVE-2026-35220MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Page 11 of 21