Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-35610 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms. | ||
| CVE-2020-13763 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2020 | In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users. | ||
| CVE-2020-10238 | Hig | 0.49 | 7.5 | 0.05 | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors. | ||
| CVE-2011-4937 | Hig | 0.49 | 7.5 | 0.02 | Feb 4, 2020 | Joomla! 1.7.1 has core information disclosure due to inadequate error checking. | ||
| CVE-2011-3629 | Hig | 0.49 | 7.5 | 0.01 | Feb 4, 2020 | Joomla! core 1.7.1 allows information disclosure due to weak encryption | ||
| CVE-2012-1562 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2020 | Joomla! core before 2.5.3 allows unauthorized password change. | ||
| CVE-2019-10946 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2019 | An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users. | ||
| CVE-2019-9713 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access. | ||
| CVE-2018-11322 | Hig | 0.49 | 7.5 | 0.02 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver. | ||
| CVE-2017-9933 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. | ||
| CVE-2016-9837 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2016 | An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as… | ||
| CVE-2008-4122 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2008 | Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | ||
| CVE-2015-8769 | Hig | 0.48 | 7.3 | 0.01 | Jan 12, 2016 | SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors. | ||
| CVE-2018-17856 | Hig | 0.47 | 7.2 | 0.02 | Oct 9, 2018 | An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution. | ||
| CVE-2025-22213 | Hig | 0.46 | — | 0.00 | Mar 11, 2025 | Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions. | ||
| CVE-2024-21726 | Med | 0.46 | 6.5 | 0.49 | Feb 29, 2024 | Inadequate content filtering leads to XSS vulnerabilities in various components. | ||
| CVE-2021-26030 | Med | 0.46 | 6.1 | 0.82 | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page | ||
| CVE-2021-23124 | Med | 0.46 | 6.1 | 0.79 | Jan 12, 2021 | An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks. | ||
| CVE-2025-22207 | Med | 0.44 | — | 0.00 | Feb 18, 2025 | Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. | ||
| CVE-2018-6377 | Med | 0.44 | 6.1 | 0.35 | Jan 30, 2018 | In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
- risk 0.49cvss 7.5epss 0.01
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
- risk 0.49cvss 7.5epss 0.05
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.
- risk 0.49cvss 7.5epss 0.02
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
- risk 0.49cvss 7.5epss 0.01
Joomla! core 1.7.1 allows information disclosure due to weak encryption
- risk 0.49cvss 7.5epss 0.01
Joomla! core before 2.5.3 allows unauthorized password change.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
- risk 0.49cvss 7.5epss 0.02
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as…
- risk 0.49cvss 7.5epss 0.01
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
- risk 0.48cvss 7.3epss 0.01
SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.47cvss 7.2epss 0.02
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
- risk 0.46cvss —epss 0.00
Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions.
- risk 0.46cvss 6.5epss 0.49
Inadequate content filtering leads to XSS vulnerabilities in various components.
- risk 0.46cvss 6.1epss 0.82
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
- risk 0.46cvss 6.1epss 0.79
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
- risk 0.44cvss —epss 0.00
Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
- risk 0.44cvss 6.1epss 0.35
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
Page 5 of 21