VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2018-11326MedMay 22, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.

  • CVE-2016-1000121MedOct 27, 2016
    risk 0.31cvss 4.8epss 0.01

    XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension

  • CVE-2026-75952MedAug 19, 2026
    risk 0.30cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install,…

  • CVE-2010-10003MedJan 4, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical was found in gesellix titlelink on Joomla. Affected by this vulnerability is an unknown functionality of the file plugin_content_title.php. The manipulation of the argument phrase leads to sql injection. The patch is named…

  • CVE-2021-26028MedMar 4, 2021
    risk 0.29cvss 5.5epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.

  • CVE-2026-73372MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

  • CVE-2026-73371MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

  • CVE-2026-48900MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

  • CVE-2026-35220MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

  • CVE-2018-25354MedMay 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with…

  • CVE-2018-25337MedMay 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify…

  • CVE-2026-21632MedApr 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Lack of output escaping for article titles leads to XSS vectors in various locations.

  • CVE-2026-21631MedApr 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Lack of output escaping leads to a XSS vector in the multilingual associations component.

  • CVE-2024-21723MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.01

    Inadequate parsing of URLs could result into an open redirect.

  • CVE-2023-39973MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

  • CVE-2023-39972MedAug 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.

  • CVE-2023-23751MedFeb 1, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.

  • CVE-2022-27909MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.01

    In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files

  • CVE-2020-15697MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.

  • CVE-2019-18674MedNov 6, 2019
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.

  • CVE-2018-17859MedOct 9, 2018
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.

  • CVE-2018-17857MedOct 9, 2018
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation.

  • CVE-2018-15880MedAug 29, 2018
    risk 0.28cvss 5.4epss 0.01

    An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.

  • CVE-2018-11327MedMay 22, 2018
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.

  • CVE-2017-16633MedNov 10, 2017
    risk 0.28cvss 4.3epss 0.02

    In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

  • CVE-2025-54476MedSep 30, 2025
    risk 0.24cvss —epss 0.00

    Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.

  • CVE-2017-14595LowSep 20, 2017
    risk 0.24cvss 3.7epss 0.02

    In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

  • CVE-2026-56290CriKEVJun 29, 2026
    risk 0.22cvss 9.8epss 0.31

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

  • CVE-2025-22212LowMar 5, 2025
    risk 0.18cvss 2.7epss 0.00

    A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend.

  • CVE-2015-8562Dec 16, 2015
    risk 0.11cvss —epss 0.98

    Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.

  • CVE-2015-7857Oct 29, 2015
    risk 0.11cvss —epss 0.94

    SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.

  • CVE-2015-7297Oct 29, 2015
    risk 0.11cvss —epss 1.00

    SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

  • CVE-2015-7858Oct 29, 2015
    risk 0.10cvss —epss 0.86

    SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.

  • CVE-2008-5053Nov 13, 2008
    risk 0.08cvss —epss 0.64

    PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

  • CVE-2014-7228Nov 3, 2014
    risk 0.07cvss —epss 0.55

    Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and…

  • CVE-2008-1505Mar 25, 2008
    risk 0.07cvss —epss 0.46

    PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php.

  • CVE-2007-2199Apr 24, 2007
    risk 0.07cvss —epss 0.47

    PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG…

  • CVE-2008-6221Feb 20, 2009
    risk 0.06cvss —epss 0.38

    PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

  • CVE-2007-5457Oct 14, 2007
    risk 0.06cvss —epss 0.38

    Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1)…

  • CVE-2007-5451Oct 14, 2007
    risk 0.06cvss —epss 0.31

    PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

  • CVE-2007-5412Oct 12, 2007
    risk 0.06cvss —epss 0.38

    Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2) allopass-error.php.

  • CVE-2007-5407Oct 12, 2007
    risk 0.06cvss —epss 0.40

    Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2) add.php, (3) history.php, and…

  • CVE-2007-5363Oct 11, 2007
    risk 0.06cvss —epss 0.31

    PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: the provenance of this…

  • CVE-2007-5362Oct 11, 2007
    risk 0.06cvss —epss 0.37

    Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2)…

  • CVE-2007-5065Sep 24, 2007
    risk 0.06cvss —epss 0.42

    PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

  • CVE-2007-4923Sep 17, 2007
    risk 0.06cvss —epss 0.42

    PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

  • CVE-2011-4804Dec 14, 2011
    risk 0.05cvss —epss 0.21

    Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2010-1983May 19, 2010
    risk 0.05cvss —epss 0.19

    Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party…

  • CVE-2010-1980May 19, 2010
    risk 0.05cvss —epss 0.19

    Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2010-1657May 3, 2010
    risk 0.05cvss —epss 0.19

    Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

Page 12 of 26