Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11358 | Med | 0.43 | 6.1 | 0.87 | Apr 20, 2019 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | ||
| CVE-2026-73336 | Med | 0.42 | 6.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||
| CVE-2026-71574 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the… | ||
| CVE-2024-40749 | Hig | 0.42 | 7.5 | 0.00 | Jan 7, 2025 | Improper Access Controls allows access to protected views. | ||
| CVE-2024-40748 | Hig | 0.42 | 7.5 | 0.00 | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. | ||
| CVE-2024-21725 | Med | 0.42 | 6.1 | 0.32 | Feb 29, 2024 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. | ||
| CVE-2021-26034 | Med | 0.42 | 6.5 | 0.01 | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo. | ||
| CVE-2021-26033 | Med | 0.42 | 6.5 | 0.01 | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint. | ||
| CVE-2019-12764 | Med | 0.42 | 6.5 | 0.01 | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users. | ||
| CVE-2018-15881 | Hig | 0.42 | 7.5 | 0.02 | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation. | ||
| CVE-2018-11321 | Med | 0.42 | 6.5 | 0.02 | May 22, 2018 | An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. | ||
| CVE-2017-7989 | Med | 0.42 | 6.5 | 0.01 | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden. | ||
| CVE-2024-21722 | Med | 0.41 | 6.3 | 0.01 | Feb 29, 2024 | The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. | ||
| CVE-2023-23750 | Med | 0.41 | 6.3 | 0.00 | Feb 1, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages. | ||
| CVE-2020-35615 | Med | 0.41 | 6.3 | 0.00 | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability. | ||
| CVE-2020-15700 | Med | 0.41 | 6.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. | ||
| CVE-2020-15695 | Med | 0.41 | 6.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. | ||
| CVE-2026-48905 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. | ||
| CVE-2026-48903 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | ||
| CVE-2026-30895 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. |
- risk 0.43cvss 6.1epss 0.87
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
- risk 0.42cvss 6.4epss 0.00
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
- risk 0.42cvss 6.5epss 0.00
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the…
- risk 0.42cvss 7.5epss 0.00
Improper Access Controls allows access to protected views.
- risk 0.42cvss 7.5epss 0.00
Lack of output escaping in the id attribute of menu lists.
- risk 0.42cvss 6.1epss 0.32
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
- risk 0.42cvss 7.5epss 0.02
An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.
- risk 0.42cvss 6.5epss 0.02
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
- risk 0.42cvss 6.5epss 0.01
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
- risk 0.41cvss 6.3epss 0.01
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
- risk 0.41cvss 6.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
- risk 0.41cvss 6.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
- risk 0.40cvss 6.1epss 0.00
Lack of input filtering leads to an XSS vector in the HTML filter code.
- risk 0.40cvss 6.1epss 0.00
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.00
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
Page 6 of 21