Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-4907 | Med | 0.35 | 5.3 | 0.01 | Jan 15, 2020 | Joomla! 1.5x through 1.5.12: Missing JEXEC Check | ||
| CVE-2019-19845 | Med | 0.35 | 5.3 | 0.01 | Dec 18, 2019 | In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. | ||
| CVE-2019-15028 | Med | 0.35 | 5.3 | 0.01 | Aug 14, 2019 | In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. | ||
| CVE-2019-6262 | Med | 0.35 | 5.4 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS. | ||
| CVE-2017-8057 | Med | 0.35 | 5.3 | 0.01 | Apr 25, 2017 | In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting. | ||
| CVE-2017-7988 | Med | 0.35 | 5.3 | 0.01 | Apr 25, 2017 | In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. | ||
| CVE-2017-7983 | Med | 0.35 | 5.3 | 0.01 | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. | ||
| CVE-2005-4650 | Med | 0.35 | 5.3 | 0.02 | Dec 31, 2005 | Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots. | ||
| CVE-2025-54477 | Med | 0.34 | 5.3 | 0.00 | Sep 30, 2025 | Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. | ||
| CVE-2022-27912 | Med | 0.34 | 5.3 | 0.01 | Oct 25, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. | ||
| CVE-2022-27911 | Med | 0.34 | 5.3 | 0.01 | Aug 31, 2022 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. | ||
| CVE-2019-6263 | Med | 0.34 | 4.8 | 0.05 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS. | ||
| CVE-2024-40747 | Med | 0.33 | 6.1 | 0.00 | Jan 7, 2025 | Various module chromes didn't properly process inputs, leading to XSS vectors. | ||
| CVE-2018-11328 | Med | 0.31 | 4.7 | 0.02 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS… | ||
| CVE-2018-11326 | Med | 0.31 | 4.8 | 0.01 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack. | ||
| CVE-2021-26028 | Med | 0.29 | 5.5 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path. | ||
| CVE-2026-73372 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. | ||
| CVE-2026-73371 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. | ||
| CVE-2026-48900 | Med | 0.28 | 4.3 | 0.00 | May 26, 2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. | ||
| CVE-2026-35220 | Med | 0.28 | 4.3 | 0.00 | May 26, 2026 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. |
- risk 0.35cvss 5.3epss 0.01
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
- risk 0.35cvss 5.3epss 0.01
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
- risk 0.35cvss 5.3epss 0.01
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.
- risk 0.35cvss 5.3epss 0.01
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
- risk 0.35cvss 5.3epss 0.01
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
- risk 0.35cvss 5.3epss 0.01
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
- risk 0.35cvss 5.3epss 0.02
Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.
- risk 0.34cvss 5.3epss 0.00
Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.
- risk 0.34cvss 4.8epss 0.05
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.
- risk 0.33cvss 6.1epss 0.00
Various module chromes didn't properly process inputs, leading to XSS vectors.
- risk 0.31cvss 4.7epss 0.02
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS…
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
- risk 0.29cvss 5.5epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
- risk 0.28cvss 4.3epss 0.00
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
- risk 0.28cvss 4.3epss 0.00
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
- risk 0.28cvss 4.3epss 0.00
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
- risk 0.28cvss 4.3epss 0.00
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Page 11 of 21