VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2020-10238HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

  • CVE-2011-4937HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.02

    Joomla! 1.7.1 has core information disclosure due to inadequate error checking.

  • CVE-2011-3629HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.01

    Joomla! core 1.7.1 allows information disclosure due to weak encryption

  • CVE-2012-1562HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Joomla! core before 2.5.3 allows unauthorized password change.

  • CVE-2019-10946HigApr 10, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.

  • CVE-2019-9713HigMar 12, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.

  • CVE-2018-11322HigMay 22, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.

  • CVE-2013-7428HigSep 7, 2017
    risk 0.49cvss 7.5epss 0.02

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.

  • CVE-2013-7432HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.01

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.

  • CVE-2017-9933HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.02

    Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.

  • CVE-2017-5214HigMay 17, 2017
    risk 0.49cvss 7.5epss 0.01

    The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a time value. This makes it easier to read arbitrary uploaded files.

  • CVE-2016-9837HigDec 16, 2016
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as…

  • CVE-2008-4122HigDec 19, 2008
    risk 0.49cvss 7.5epss 0.01

    Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

  • CVE-2015-8769HigJan 12, 2016
    risk 0.48cvss 7.3epss 0.01

    SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2026-65947HigJul 29, 2026
    risk 0.47cvss 7.3epss 0.00

    Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

  • CVE-2018-17856HigOct 9, 2018
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.

  • CVE-2016-10379HigMay 29, 2017
    risk 0.47cvss 7.2epss 0.01

    The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.

  • CVE-2016-1000122HigOct 27, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension

  • CVE-2016-1000120HigOct 27, 2016
    risk 0.47cvss 7.2epss 0.02

    SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

  • CVE-2016-1000119HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

  • CVE-2016-1000118HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS & SQLi in HugeIT slideshow v1.0.4

  • CVE-2016-1000117HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS & SQLi in HugeIT slideshow v1.0.4

  • CVE-2026-78081HigSep 15, 2026
    risk 0.46cvss —epss 0.00

    Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a victim's active checkout session could silently overwrite the billing or shipping address before…

  • CVE-2026-81564HigSep 14, 2026
    risk 0.46cvss —epss 0.00

    Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same…

  • CVE-2026-78083HigSep 10, 2026
    risk 0.46cvss —epss 0.00

    Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without…

  • CVE-2019-25761HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to index.php with…

  • CVE-2019-25759HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with…

  • CVE-2019-25757HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL…

  • CVE-2019-25749HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL…

  • CVE-2017-20265HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the…

  • CVE-2017-20264HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the…

  • CVE-2018-25381HigMay 25, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search…

  • CVE-2018-25380HigMay 25, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view…

  • CVE-2020-37226HigMay 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby'…

  • CVE-2020-37224HigMay 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby'…

  • CVE-2025-54297HigJul 23, 2025
    risk 0.46cvss —epss 0.00

    A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.

  • CVE-2025-54296HigJul 23, 2025
    risk 0.46cvss —epss 0.00

    A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.

  • CVE-2025-22213HigMar 11, 2025
    risk 0.46cvss —epss 0.00

    Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions.

  • CVE-2024-21726MedFeb 29, 2024
    risk 0.46cvss 6.5epss 0.49

    Inadequate content filtering leads to XSS vulnerabilities in various components.

  • CVE-2021-26030MedApr 14, 2021
    risk 0.46cvss 6.1epss 0.82

    An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

  • CVE-2021-23124MedJan 12, 2021
    risk 0.46cvss 6.1epss 0.79

    An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

  • CVE-2026-79701MedSep 14, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's…

  • CVE-2026-81565MedSep 14, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and…

  • CVE-2026-79700MedSep 14, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the…

  • CVE-2026-78085MedSep 10, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

  • CVE-2026-78374MedSep 10, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled)…

  • CVE-2026-78303MedSep 10, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.

  • CVE-2026-78070MedAug 28, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.

  • CVE-2026-77034MedAug 27, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.

  • CVE-2026-76609MedAug 22, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

Page 7 of 26