VYPR
Vendor

Joomla

Joomla, also styled Joomla! and sometimes abbreviated as J!, is a free and open-source content management system (CMS) for publishing web content on websites. Web content applications include discussion forums, photo galleries, e-Commerce and user communities, and numerous other web-based applications. Joomla is developed by a community of volunteers supported with the legal, organisational and financial resources of Open Source Matters, Inc.

Founded 2005
Products
802
CVEs
1,191
Across products
554
Status
Private

Products

802
View all 802 products →

Recent CVEs

1,191
View all 1,191 CVEs →
  • CVE-2026-48908CriKEVJun 20, 2026
    risk 0.83cvss 9.8epss 0.88

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

  • CVE-2016-10033CriKEVDec 30, 2016
    risk 0.80cvss 9.8epss 1.00

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

  • CVE-2026-48907CriKEVJun 5, 2026
    risk 0.77cvss epss 0.66

    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

  • CVE-2017-8917CriMay 17, 2017
    risk 0.75cvss 9.8epss 1.00

    SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-8869CriNov 4, 2016
    risk 0.74cvss 9.8epss 0.97

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.

  • CVE-2018-17254CriSep 20, 2018
    risk 0.73cvss 9.8epss 0.83

    The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.

  • CVE-2011-4908CriFeb 12, 2020
    risk 0.71cvss 9.8epss 0.56

    TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

  • CVE-2018-7314CriFeb 22, 2018
    risk 0.71cvss 9.8epss 0.58

    SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

  • CVE-2018-6605CriFeb 5, 2018
    risk 0.71cvss 9.8epss 0.58

    SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

  • CVE-2019-10945CriApr 10, 2019
    risk 0.70cvss 9.8epss 0.38

    An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.

  • CVE-2018-6580CriFeb 2, 2018
    risk 0.70cvss 9.8epss 0.36

    Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

  • CVE-2018-6396CriFeb 17, 2018
    risk 0.69cvss 9.8epss 0.24

    SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.

  • CVE-2019-12765CriJun 11, 2019
    risk 0.68cvss 9.8epss 0.10

    An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.

  • CVE-2018-7313CriFeb 22, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

  • CVE-2016-10045CriDec 30, 2016
    risk 0.68cvss 9.8epss 0.98

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail…

  • CVE-2011-4906CriFeb 12, 2020
    risk 0.67cvss 9.8epss 0.10

    Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

  • CVE-2019-9184CriFeb 26, 2019
    risk 0.67cvss 9.8epss 0.09

    SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

  • CVE-2018-17397CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.

  • CVE-2018-17394CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.

  • CVE-2018-17385CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.