VYPR

Joomla!

by Joomla

Source repositories

CVEs (418)

  • CVE-2026-30894MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the content history component.

  • CVE-2026-25901MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the multilingual associations component.

  • CVE-2026-25900MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the feed modules.

  • CVE-2026-23898HigApr 1, 2026
    risk 0.40cvss 7.2epss 0.00

    Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

  • CVE-2026-21629HigApr 1, 2026
    risk 0.40cvss 7.3epss 0.00

    The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.

  • CVE-2025-63083MedJan 6, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the pagebreak plugin.

  • CVE-2025-63082MedJan 6, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

  • CVE-2024-40743MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

  • CVE-2024-27186MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

  • CVE-2024-27184MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

  • CVE-2024-26279MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    The wrapper extensions do not correctly validate inputs, leading to XSS vectors.

  • CVE-2024-26278MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    The Custom Fields component not correctly filter inputs, leading to a XSS vector.

  • CVE-2024-21731MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.

  • CVE-2024-21729MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

  • CVE-2024-21724MedFeb 29, 2024
    risk 0.40cvss 6.1epss 0.01

    Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.

  • CVE-2023-23754MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

  • CVE-2022-27914MedNov 8, 2022
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.

  • CVE-2022-27913MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

  • CVE-2022-23801MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.

  • CVE-2022-23800MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.

Page 7 of 21