VYPR

Joomla!

by Joomla

Source repositories

CVEs (418)

  • CVE-2023-23752MedKEVFeb 16, 2023
    risk 0.50cvss 5.3epss 1.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

  • CVE-2026-73337HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2026-48901HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

  • CVE-2026-48897HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2026-48896HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2026-40384HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

  • CVE-2025-25227HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2024-27187HigAug 20, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Access Controls allows backend users to overwrite their username when disallowed.

  • CVE-2023-40626HigNov 29, 2023
    risk 0.49cvss 7.5epss 0.01

    The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

  • CVE-2023-23755HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

  • CVE-2022-23793HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.

  • CVE-2021-26038HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.

  • CVE-2021-26036HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.

  • CVE-2010-1434HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and…

  • CVE-2010-1432HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

  • CVE-2021-23132HigMar 4, 2021
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads

  • CVE-2021-23131HigMar 4, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.

  • CVE-2020-35616HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

  • CVE-2020-35612HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.

  • CVE-2020-35611HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.

Page 4 of 21