VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2026-76608MedAug 22, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.

  • CVE-2026-76603MedAug 22, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

  • CVE-2026-76601MedAug 22, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.

  • CVE-2026-76600MedAug 22, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.

  • CVE-2026-67361MedAug 21, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the…

  • CVE-2026-76610MedAug 20, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

  • CVE-2026-75951MedAug 19, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

  • CVE-2026-75950MedAug 19, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated…

  • CVE-2025-22207MedFeb 18, 2025
    risk 0.44cvss —epss 0.00

    Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.

  • CVE-2018-6377MedJan 30, 2018
    risk 0.44cvss 6.1epss 0.35

    In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox

  • CVE-2010-0467MedFeb 2, 2010
    risk 0.44cvss 5.8epss 0.43

    Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.

  • CVE-2013-4692MedDec 27, 2019
    risk 0.43cvss 6.1epss 0.02

    Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS

  • CVE-2019-11358MedApr 20, 2019
    risk 0.43cvss 6.1epss 0.87

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

  • CVE-2018-10068MedApr 12, 2018
    risk 0.43cvss 6.1epss 0.05

    The jDownloads extension before 3.2.59 for Joomla! has XSS.

  • CVE-2026-73336MedAug 18, 2026
    risk 0.42cvss 6.4epss 0.00

    Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

  • CVE-2026-71574MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the…

  • CVE-2026-66493MedAug 7, 2026
    risk 0.42cvss —epss 0.00

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.

  • CVE-2019-25740MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2…

  • CVE-2024-40749HigJan 7, 2025
    risk 0.42cvss 7.5epss 0.00

    Improper Access Controls allows access to protected views.

  • CVE-2024-40748HigJan 7, 2025
    risk 0.42cvss 7.5epss 0.00

    Lack of output escaping in the id attribute of menu lists.

  • CVE-2024-21725MedFeb 29, 2024
    risk 0.42cvss 6.1epss 0.32

    Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.

  • CVE-2021-26034MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.

  • CVE-2021-26033MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

  • CVE-2020-13424MedMay 23, 2020
    risk 0.42cvss 6.5epss 0.02

    The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.

  • CVE-2019-12764MedJun 11, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.

  • CVE-2019-9921MedMar 29, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.

  • CVE-2018-15881HigAug 29, 2018
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.

  • CVE-2018-11321MedMay 22, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.

  • CVE-2017-7989MedApr 25, 2017
    risk 0.42cvss 6.5epss 0.01

    In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.

  • CVE-2026-82190MedSep 15, 2026
    risk 0.41cvss —epss 0.00

    Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining…

  • CVE-2026-67360MedAug 21, 2026
    risk 0.41cvss —epss 0.00

    Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was…

  • CVE-2026-67287MedAug 12, 2026
    risk 0.41cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

  • CVE-2026-67286MedAug 12, 2026
    risk 0.41cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

  • CVE-2024-21722MedFeb 29, 2024
    risk 0.41cvss 6.3epss 0.01

    The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

  • CVE-2023-23750MedFeb 1, 2023
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.

  • CVE-2020-35615MedDec 28, 2020
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.

  • CVE-2020-15700MedJul 15, 2020
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.

  • CVE-2020-15695MedJul 15, 2020
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.

  • CVE-2026-66490MedJul 29, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

  • CVE-2026-65946MedJul 29, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

  • CVE-2019-25760MedJun 19, 2026
    risk 0.40cvss 6.2epss 0.01

    Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task…

  • CVE-2026-48905MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of input filtering leads to an XSS vector in the HTML filter code.

  • CVE-2026-48903MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

  • CVE-2026-30895MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the readmore links for com_content.

  • CVE-2026-30894MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the content history component.

  • CVE-2026-25901MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the multilingual associations component.

  • CVE-2026-25900MedMay 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the feed modules.

  • CVE-2023-54364MedApr 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the…

  • CVE-2023-54363MedApr 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and…

  • CVE-2023-54362MedApr 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the…

Page 8 of 26