Vendor CVEs
Joomla
All CVEs
1,291 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9714 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS. | ||
| CVE-2019-9712 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS. | ||
| CVE-2019-9711 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2019 | An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS. | ||
| CVE-2019-7744 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability. | ||
| CVE-2019-7742 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector. | ||
| CVE-2019-7741 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS. | ||
| CVE-2019-7740 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector. | ||
| CVE-2019-7739 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain… | ||
| CVE-2019-6264 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability. | ||
| CVE-2019-6261 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability. | ||
| CVE-2018-12711 | Med | 0.40 | 6.1 | 0.02 | Jun 26, 2018 | An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or… | ||
| CVE-2018-6378 | Med | 0.40 | 6.1 | 0.02 | May 22, 2018 | In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager. | ||
| CVE-2018-6380 | Med | 0.40 | 6.1 | 0.02 | Jan 30, 2018 | In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. | ||
| CVE-2018-6379 | Med | 0.40 | 6.1 | 0.02 | Jan 30, 2018 | In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability. | ||
| CVE-2015-5608 | Med | 0.40 | 6.1 | 0.01 | Sep 20, 2017 | Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1. | ||
| CVE-2013-7433 | Med | 0.40 | 6.1 | 0.01 | Aug 29, 2017 | Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!. | ||
| CVE-2013-7430 | Med | 0.40 | 6.1 | 0.01 | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter. | ||
| CVE-2017-11612 | Med | 0.40 | 6.1 | 0.01 | Jul 26, 2017 | In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components. | ||
| CVE-2017-9934 | Med | 0.40 | 6.1 | 0.03 | Jul 17, 2017 | Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability. | ||
| CVE-2017-7987 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component. | ||
| CVE-2017-7986 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components. | ||
| CVE-2017-7985 | Med | 0.40 | 6.1 | 0.02 | Apr 25, 2017 | In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components. | ||
| CVE-2017-7984 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. | ||
| CVE-2016-1000114 | Med | 0.40 | 6.1 | 0.01 | Oct 6, 2016 | XSS in huge IT gallery v1.1.5 for Joomla | ||
| CVE-2018-11324 | Med | 0.38 | 5.9 | 0.01 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated. | ||
| CVE-2014-9686 | Med | 0.38 | 5.9 | 0.02 | Sep 28, 2017 | The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete… | ||
| CVE-2015-4072 | Med | 0.38 | 5.4 | 0.03 | Sep 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message. | ||
| CVE-2015-4071 | Med | 0.38 | 5.3 | 0.09 | Aug 18, 2017 | The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}. | ||
| CVE-2024-2045 | Med | 0.36 | 5.5 | 0.00 | Mar 1, 2024 | Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments. | ||
| CVE-2026-72531 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | ||
| CVE-2026-71572 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. | ||
| CVE-2026-72532 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. | ||
| CVE-2026-21624 | Med | 0.35 | 5.4 | 0.00 | Jan 16, 2026 | Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla. | ||
| CVE-2024-40745 | Med | 0.35 | 5.4 | 0.00 | Dec 4, 2024 | Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8. | ||
| CVE-2024-21730 | Med | 0.35 | 5.4 | 0.00 | Jul 9, 2024 | The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. | ||
| CVE-2022-23794 | Med | 0.35 | 5.3 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application. | ||
| CVE-2021-26037 | Med | 0.35 | 5.3 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked. | ||
| CVE-2021-26031 | Med | 0.35 | 5.3 | 0.01 | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI. | ||
| CVE-2021-26029 | Med | 0.35 | 5.3 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field. | ||
| CVE-2021-26027 | Med | 0.35 | 5.3 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. | ||
| CVE-2021-23126 | Med | 0.35 | 5.3 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret. | ||
| CVE-2021-23123 | Med | 0.35 | 5.3 | 0.01 | Jan 12, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules. | ||
| CVE-2020-35614 | Med | 0.35 | 5.3 | 0.01 | Dec 28, 2020 | An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page. | ||
| CVE-2020-15699 | Med | 0.35 | 5.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. | ||
| CVE-2020-15698 | Med | 0.35 | 5.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials | ||
| CVE-2020-11891 | Med | 0.35 | 5.3 | 0.01 | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups. | ||
| CVE-2020-11890 | Med | 0.35 | 5.3 | 0.03 | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. | ||
| CVE-2020-11889 | Med | 0.35 | 5.3 | 0.01 | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups. | ||
| CVE-2020-10240 | Med | 0.35 | 5.3 | 0.01 | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses. | ||
| CVE-2020-9364 | Med | 0.35 | 5.3 | 0.03 | Mar 4, 2020 | An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could… |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.
- risk 0.40cvss 6.1epss 0.02
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or…
- risk 0.40cvss 6.1epss 0.02
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
- risk 0.40cvss 6.1epss 0.02
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
- risk 0.40cvss 6.1epss 0.02
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.
- risk 0.40cvss 6.1epss 0.01
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.03
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.02
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
- risk 0.40cvss 6.1epss 0.01
XSS in huge IT gallery v1.1.5 for Joomla
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.
- risk 0.38cvss 5.9epss 0.02
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete…
- risk 0.38cvss 5.4epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.
- risk 0.38cvss 5.3epss 0.09
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.
- risk 0.36cvss 5.5epss 0.00
Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.
- risk 0.35cvss 5.4epss 0.00
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
- risk 0.35cvss 5.4epss 0.00
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
- risk 0.35cvss 5.4epss 0.00
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
- risk 0.35cvss 5.4epss 0.00
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
- risk 0.35cvss 5.4epss 0.00
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
- risk 0.35cvss 5.4epss 0.00
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
- risk 0.35cvss 5.3epss 0.03
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
- risk 0.35cvss 5.3epss 0.03
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could…
Page 10 of 26