VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2021-26040CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.

  • CVE-2021-23128CriMar 4, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within…

  • CVE-2021-23127CriMar 4, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.

  • CVE-2011-1151CriFeb 5, 2020
    risk 0.59cvss 9.1epss 0.02

    Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

  • CVE-2019-9918CriMar 29, 2019
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.

  • CVE-2026-78078HigAug 31, 2026
    risk 0.58cvss —epss 0.00

    Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict…

  • CVE-2026-82189HigSep 15, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or…

  • CVE-2026-81568HigSep 15, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concatenating the configured attachment folder…

  • CVE-2026-81567HigSep 15, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored…

  • CVE-2026-78064HigSep 3, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the `carts` view's tasks a wildcard `true` ACL, and FOF only enforces CSRF tokens on back-end HTML requests,…

  • CVE-2026-77999HigSep 3, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN()`) accepted `UNVERIFIED` and any non-`INVALID` response…

  • CVE-2026-76599HigAug 22, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.

  • CVE-2026-76598HigAug 22, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.

  • CVE-2026-76597HigAug 22, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.

  • CVE-2026-76596HigAug 22, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table

  • CVE-2026-67359HigAug 21, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to render the full checkout confirmation page for that order, including line items, prices,…

  • CVE-2026-75956HigAug 19, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated…

  • CVE-2026-66494HigAug 7, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder…

  • CVE-2026-65944HigJul 29, 2026
    risk 0.57cvss 8.8epss 0.00

    Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

  • CVE-2026-57828HigJul 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

  • CVE-2019-25758HigJun 19, 2026
    risk 0.57cvss 8.8epss 0.01

    Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee…

  • CVE-2026-21625HigJan 16, 2026
    risk 0.57cvss 8.8epss 0.00

    User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

  • CVE-2025-54475HigAug 15, 2025
    risk 0.57cvss —epss 0.00

    A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

  • CVE-2022-23799CriMar 30, 2022
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

  • CVE-2020-25751HigSep 18, 2020
    risk 0.57cvss 8.8epss 0.02

    The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.

  • CVE-2020-13996HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.01

    The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

  • CVE-2020-13760HigJun 2, 2020
    risk 0.57cvss 8.8epss 0.01

    In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

  • CVE-2020-10241HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

  • CVE-2020-10239HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

  • CVE-2020-8420HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

  • CVE-2020-8419HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

  • CVE-2019-18650HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

  • CVE-2019-14654HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.02

    In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.

  • CVE-2019-11831CriMay 9, 2019
    risk 0.57cvss 9.8epss 0.05

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

  • CVE-2019-9920HigMar 29, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.

  • CVE-2018-17858HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

  • CVE-2018-17855HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.

  • CVE-2018-15882CriAug 29, 2018
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.

  • CVE-2018-12712HigJun 26, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.

  • CVE-2018-11323HigMay 22, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.

  • CVE-2017-11364HigAug 2, 2017
    risk 0.57cvss 8.8epss 0.02

    The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.

  • CVE-2026-78375HigSep 14, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it…

  • CVE-2026-78302HigSep 10, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly…

  • CVE-2026-78077HigAug 31, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual…

  • CVE-2026-77027HigAug 22, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.

  • CVE-2026-74252HigAug 21, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a…

  • CVE-2026-76613HigAug 21, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.

  • CVE-2026-76612HigAug 21, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.

  • CVE-2026-76564HigAug 20, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

  • CVE-2026-75948HigAug 20, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.

Page 4 of 26