Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23752 | Med | 0.50 | 5.3 | 1.00 | KEV | Feb 16, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | |
| CVE-2026-73337 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. | ||
| CVE-2026-48901 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | ||
| CVE-2026-48897 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | ||
| CVE-2026-48896 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | ||
| CVE-2026-40384 | Hig | 0.49 | 7.5 | 0.00 | May 26, 2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | ||
| CVE-2025-25227 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2025 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | ||
| CVE-2024-27187 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2024 | Improper Access Controls allows backend users to overwrite their username when disallowed. | ||
| CVE-2023-40626 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2023 | The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. | ||
| CVE-2023-23755 | Hig | 0.49 | 7.5 | 0.01 | May 30, 2023 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods. | ||
| CVE-2022-23793 | Hig | 0.49 | 7.5 | 0.02 | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. | ||
| CVE-2021-26038 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already. | ||
| CVE-2021-26036 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table. | ||
| CVE-2010-1434 | Hig | 0.49 | 7.5 | 0.01 | Jun 21, 2021 | Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and… | ||
| CVE-2010-1432 | Hig | 0.49 | 7.5 | 0.01 | Jun 21, 2021 | Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable. | ||
| CVE-2021-23132 | Hig | 0.49 | 7.5 | 0.07 | Mar 4, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads | ||
| CVE-2021-23131 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager. | ||
| CVE-2020-35616 | Hig | 0.49 | 7.5 | 0.06 | Dec 28, 2020 | An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. | ||
| CVE-2020-35612 | Hig | 0.49 | 7.5 | 0.02 | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability. | ||
| CVE-2020-35611 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values. |
- risk 0.50cvss 5.3epss 1.00
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- risk 0.49cvss 7.5epss 0.00
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
- risk 0.49cvss 7.5epss 0.00
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
- risk 0.49cvss 7.5epss 0.00
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
- risk 0.49cvss 7.5epss 0.00
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
- risk 0.49cvss 7.5epss 0.00
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
- risk 0.49cvss 7.5epss 0.00
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
- risk 0.49cvss 7.5epss 0.00
Improper Access Controls allows backend users to overwrite their username when disallowed.
- risk 0.49cvss 7.5epss 0.01
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.
- risk 0.49cvss 7.5epss 0.01
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and…
- risk 0.49cvss 7.5epss 0.01
Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
- risk 0.49cvss 7.5epss 0.07
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
- risk 0.49cvss 7.5epss 0.06
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
Page 4 of 21