Vendor CVEs
Joomla
All CVEs
1,291 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-76608 | Med | 0.45 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks. | ||
| CVE-2026-76603 | Med | 0.45 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users. | ||
| CVE-2026-76601 | Med | 0.45 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks. | ||
| CVE-2026-76600 | Med | 0.45 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks. | ||
| CVE-2026-67361 | Med | 0.45 | — | 0.00 | Aug 21, 2026 | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the… | ||
| CVE-2026-76610 | Med | 0.45 | — | 0.00 | Aug 20, 2026 | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users. | ||
| CVE-2026-75951 | Med | 0.45 | — | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | ||
| CVE-2026-75950 | Med | 0.45 | — | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated… | ||
| CVE-2025-22207 | Med | 0.44 | — | 0.00 | Feb 18, 2025 | Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. | ||
| CVE-2018-6377 | Med | 0.44 | 6.1 | 0.35 | Jan 30, 2018 | In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox | ||
| CVE-2010-0467 | Med | 0.44 | 5.8 | 0.43 | Feb 2, 2010 | Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php. | ||
| CVE-2013-4692 | Med | 0.43 | 6.1 | 0.02 | Dec 27, 2019 | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS | ||
| CVE-2019-11358 | Med | 0.43 | 6.1 | 0.87 | Apr 20, 2019 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | ||
| CVE-2018-10068 | Med | 0.43 | 6.1 | 0.05 | Apr 12, 2018 | The jDownloads extension before 3.2.59 for Joomla! has XSS. | ||
| CVE-2026-73336 | Med | 0.42 | 6.4 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||
| CVE-2026-71574 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the… | ||
| CVE-2026-66493 | Med | 0.42 | — | 0.00 | Aug 7, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities. | ||
| CVE-2019-25740 | Med | 0.42 | 6.5 | 0.00 | Jun 4, 2026 | Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2… | ||
| CVE-2024-40749 | Hig | 0.42 | 7.5 | 0.00 | Jan 7, 2025 | Improper Access Controls allows access to protected views. | ||
| CVE-2024-40748 | Hig | 0.42 | 7.5 | 0.00 | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. | ||
| CVE-2024-21725 | Med | 0.42 | 6.1 | 0.32 | Feb 29, 2024 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. | ||
| CVE-2021-26034 | Med | 0.42 | 6.5 | 0.01 | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo. | ||
| CVE-2021-26033 | Med | 0.42 | 6.5 | 0.01 | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint. | ||
| CVE-2020-13424 | Med | 0.42 | 6.5 | 0.02 | May 23, 2020 | The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure. | ||
| CVE-2019-12764 | Med | 0.42 | 6.5 | 0.01 | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users. | ||
| CVE-2019-9921 | Med | 0.42 | 6.5 | 0.01 | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user. | ||
| CVE-2018-15881 | Hig | 0.42 | 7.5 | 0.02 | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation. | ||
| CVE-2018-11321 | Med | 0.42 | 6.5 | 0.02 | May 22, 2018 | An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. | ||
| CVE-2017-7989 | Med | 0.42 | 6.5 | 0.01 | Apr 25, 2017 | In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden. | ||
| CVE-2026-82190 | Med | 0.41 | — | 0.00 | Sep 15, 2026 | Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining… | ||
| CVE-2026-67360 | Med | 0.41 | — | 0.00 | Aug 21, 2026 | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was… | ||
| CVE-2026-67287 | Med | 0.41 | — | 0.00 | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | ||
| CVE-2026-67286 | Med | 0.41 | — | 0.00 | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | ||
| CVE-2024-21722 | Med | 0.41 | 6.3 | 0.01 | Feb 29, 2024 | The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. | ||
| CVE-2023-23750 | Med | 0.41 | 6.3 | 0.00 | Feb 1, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages. | ||
| CVE-2020-35615 | Med | 0.41 | 6.3 | 0.00 | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability. | ||
| CVE-2020-15700 | Med | 0.41 | 6.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. | ||
| CVE-2020-15695 | Med | 0.41 | 6.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. | ||
| CVE-2026-66490 | Med | 0.40 | 6.1 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | ||
| CVE-2026-65946 | Med | 0.40 | 6.1 | 0.00 | Jul 29, 2026 | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | ||
| CVE-2019-25760 | Med | 0.40 | 6.2 | 0.01 | Jun 19, 2026 | Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task… | ||
| CVE-2026-48905 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. | ||
| CVE-2026-48903 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | ||
| CVE-2026-30895 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | ||
| CVE-2026-30894 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the content history component. | ||
| CVE-2026-25901 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | ||
| CVE-2026-25900 | Med | 0.40 | 6.1 | 0.00 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the feed modules. | ||
| CVE-2023-54364 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2026 | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the… | ||
| CVE-2023-54363 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2026 | Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and… | ||
| CVE-2023-54362 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2026 | Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the… |
- risk 0.45cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.
- risk 0.45cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.
- risk 0.45cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.
- risk 0.45cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.
- risk 0.45cvss —epss 0.00
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the…
- risk 0.45cvss —epss 0.00
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.
- risk 0.45cvss —epss 0.00
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
- risk 0.45cvss —epss 0.00
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated…
- risk 0.44cvss —epss 0.00
Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
- risk 0.44cvss 6.1epss 0.35
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
- risk 0.44cvss 5.8epss 0.43
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
- risk 0.43cvss 6.1epss 0.02
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
- risk 0.43cvss 6.1epss 0.87
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
- risk 0.43cvss 6.1epss 0.05
The jDownloads extension before 3.2.59 for Joomla! has XSS.
- risk 0.42cvss 6.4epss 0.00
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
- risk 0.42cvss 6.5epss 0.00
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the…
- risk 0.42cvss —epss 0.00
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.
- risk 0.42cvss 6.5epss 0.00
Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2…
- risk 0.42cvss 7.5epss 0.00
Improper Access Controls allows access to protected views.
- risk 0.42cvss 7.5epss 0.00
Lack of output escaping in the id attribute of menu lists.
- risk 0.42cvss 6.1epss 0.32
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.
- risk 0.42cvss 6.5epss 0.02
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.
- risk 0.42cvss 7.5epss 0.02
An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.
- risk 0.42cvss 6.5epss 0.02
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
- risk 0.42cvss 6.5epss 0.01
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
- risk 0.41cvss —epss 0.00
Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining…
- risk 0.41cvss —epss 0.00
Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was…
- risk 0.41cvss —epss 0.00
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.
- risk 0.41cvss —epss 0.00
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.
- risk 0.41cvss 6.3epss 0.01
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
- risk 0.41cvss 6.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
- risk 0.41cvss 6.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
- risk 0.40cvss 6.1epss 0.00
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
- risk 0.40cvss 6.1epss 0.00
Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
- risk 0.40cvss 6.2epss 0.01
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task…
- risk 0.40cvss 6.1epss 0.00
Lack of input filtering leads to an XSS vector in the HTML filter code.
- risk 0.40cvss 6.1epss 0.00
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.00
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
- risk 0.40cvss 6.1epss 0.00
Lack of output escaping leads to a XSS vector in the content history component.
- risk 0.40cvss 6.1epss 0.00
Lack of output escaping leads to a XSS vector in the multilingual associations component.
- risk 0.40cvss 6.1epss 0.00
Lack of output escaping leads to a XSS vector in the feed modules.
- risk 0.40cvss 6.1epss 0.00
Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the…
- risk 0.40cvss 6.1epss 0.00
Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and…
- risk 0.40cvss 6.1epss 0.00
Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the…
Page 8 of 26