VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2011-4912MedFeb 4, 2020
    risk 0.35cvss 5.3epss 0.01

    Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

  • CVE-2011-3595MedJan 22, 2020
    risk 0.35cvss 5.4epss 0.01

    Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.

  • CVE-2011-4907MedJan 15, 2020
    risk 0.35cvss 5.3epss 0.01

    Joomla! 1.5x through 1.5.12: Missing JEXEC Check

  • CVE-2019-19845MedDec 18, 2019
    risk 0.35cvss 5.3epss 0.01

    In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.

  • CVE-2019-15120MedAug 16, 2019
    risk 0.35cvss 5.4epss 0.01

    The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

  • CVE-2019-15028MedAug 14, 2019
    risk 0.35cvss 5.3epss 0.01

    In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.

  • CVE-2019-9919MedMar 29, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.

  • CVE-2019-6262MedJan 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.

  • CVE-2015-3619MedFeb 6, 2018
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company."

  • CVE-2013-7431MedAug 29, 2017
    risk 0.35cvss 5.3epss 0.01

    Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.

  • CVE-2017-8057MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.

  • CVE-2017-7988MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.

  • CVE-2017-7983MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.

  • CVE-2005-4650MedDec 31, 2005
    risk 0.35cvss 5.3epss 0.02

    Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.

  • CVE-2026-82191MedSep 15, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes…

  • CVE-2026-85196MedSep 14, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context…

  • CVE-2026-78000MedSep 3, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host,…

  • CVE-2026-78079MedAug 31, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.

  • CVE-2026-77990MedAug 27, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to…

  • CVE-2026-77989MedAug 27, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.

  • CVE-2026-77993MedAug 24, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.

  • CVE-2026-67358MedAug 21, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also…

  • CVE-2026-76569MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

  • CVE-2026-76565MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

  • CVE-2026-67366MedAug 14, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

  • CVE-2026-66489MedJul 29, 2026
    risk 0.34cvss 5.3epss 0.00

    Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

  • CVE-2026-66488MedJul 29, 2026
    risk 0.34cvss 5.3epss 0.00

    Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

  • CVE-2018-25327MedMay 17, 2026
    risk 0.34cvss 5.3epss 0.00

    Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete…

  • CVE-2025-54477MedSep 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.

  • CVE-2025-50126MedJul 18, 2025
    risk 0.34cvss —epss 0.00

    A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text] parameter.

  • CVE-2023-39974MedAug 17, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.

  • CVE-2022-27912MedOct 25, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.

  • CVE-2022-27911MedAug 31, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.

  • CVE-2019-6263MedJan 16, 2019
    risk 0.34cvss 4.8epss 0.05

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.

  • CVE-2026-81566MedSep 14, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the…

  • CVE-2026-78076MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or…

  • CVE-2026-78075MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image…

  • CVE-2026-77035MedAug 27, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their…

  • CVE-2026-77997MedAug 25, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules…

  • CVE-2026-67362MedAug 21, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the…

  • CVE-2026-75955MedAug 19, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.

  • CVE-2026-71570MedAug 14, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.

  • CVE-2025-50058MedJul 18, 2025
    risk 0.33cvss —epss 0.00

    A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.

  • CVE-2024-40747MedJan 7, 2025
    risk 0.33cvss 6.1epss 0.00

    Various module chromes didn't properly process inputs, leading to XSS vectors.

  • CVE-2025-22209MedFeb 15, 2025
    risk 0.31cvss 4.7epss 0.00

    A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.

  • CVE-2025-22208MedFeb 15, 2025
    risk 0.31cvss 4.7epss 0.01

    A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.

  • CVE-2025-22206MedFeb 4, 2025
    risk 0.31cvss 4.7epss 0.10

    A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.

  • CVE-2015-7344MedMar 9, 2020
    risk 0.31cvss 4.8epss 0.01

    HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].

  • CVE-2018-18276MedApr 26, 2019
    risk 0.31cvss 4.8epss 0.01

    XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel.

  • CVE-2018-11328MedMay 22, 2018
    risk 0.31cvss 4.7epss 0.02

    An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS…

Page 11 of 26