Vendor CVEs
Joomla
All CVEs
1,291 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-54361 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2026 | Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter… | ||
| CVE-2023-54360 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2026 | Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers… | ||
| CVE-2026-23898 | Hig | 0.40 | 7.2 | 0.00 | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. | ||
| CVE-2026-21629 | Hig | 0.40 | 7.3 | 0.00 | Apr 1, 2026 | The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers. | ||
| CVE-2025-63083 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2026 | Lack of output escaping leads to a XSS vector in the pagebreak plugin. | ||
| CVE-2025-63082 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. | ||
| CVE-2025-30084 | Med | 0.40 | 6.1 | 0.00 | Jun 5, 2025 | A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code… | ||
| CVE-2024-40743 | Med | 0.40 | 6.1 | 0.00 | Aug 20, 2024 | The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. | ||
| CVE-2024-27186 | Med | 0.40 | 6.1 | 0.00 | Aug 20, 2024 | The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | ||
| CVE-2024-27184 | Med | 0.40 | 6.1 | 0.00 | Aug 20, 2024 | Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. | ||
| CVE-2024-27183 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | XSS vulnerability in DJ-HelpfulArticles component for Joomla. | ||
| CVE-2024-26279 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | The wrapper extensions do not correctly validate inputs, leading to XSS vectors. | ||
| CVE-2024-26278 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | The Custom Fields component not correctly filter inputs, leading to a XSS vector. | ||
| CVE-2024-21731 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. | ||
| CVE-2024-21729 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. | ||
| CVE-2024-21724 | Med | 0.40 | 6.1 | 0.01 | Feb 29, 2024 | Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. | ||
| CVE-2024-21727 | Med | 0.40 | 6.1 | 0.00 | Feb 15, 2024 | XSS vulnerability in DP Calendar component for Joomla. | ||
| CVE-2023-40659 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla. | ||
| CVE-2023-40658 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. | ||
| CVE-2023-40657 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla. | ||
| CVE-2023-40656 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Quickform component for Joomla. | ||
| CVE-2023-40655 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla. | ||
| CVE-2023-40628 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Extplorer component for Joomla. | ||
| CVE-2023-40627 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the LivingWord component for Joomla. | ||
| CVE-2023-39971 | Med | 0.40 | 6.1 | 0.00 | Aug 17, 2023 | Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3. | ||
| CVE-2023-38045 | Med | 0.40 | 6.1 | 0.00 | Aug 7, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements. | ||
| CVE-2023-23754 | Med | 0.40 | 6.1 | 0.00 | May 30, 2023 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. | ||
| CVE-2022-27914 | Med | 0.40 | 6.1 | 0.00 | Nov 8, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media. | ||
| CVE-2022-27913 | Med | 0.40 | 6.1 | 0.00 | Oct 25, 2022 | An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components. | ||
| CVE-2022-27910 | Med | 0.40 | 6.1 | 0.01 | Jul 10, 2022 | In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function | ||
| CVE-2022-23801 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media. | ||
| CVE-2022-23800 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. | ||
| CVE-2022-23798 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. | ||
| CVE-2022-23796 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2022 | An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields. | ||
| CVE-2021-26039 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability. | ||
| CVE-2021-26035 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability. | ||
| CVE-2021-26032 | Med | 0.40 | 6.1 | 0.01 | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors. | ||
| CVE-2021-23130 | Med | 0.40 | 6.1 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. | ||
| CVE-2021-23129 | Med | 0.40 | 6.1 | 0.01 | Mar 4, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues. | ||
| CVE-2021-23125 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors. | ||
| CVE-2020-24599 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. | ||
| CVE-2020-24598 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. | ||
| CVE-2020-15696 | Med | 0.40 | 6.1 | 0.03 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. | ||
| CVE-2020-13762 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2020 | In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. | ||
| CVE-2020-13761 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2020 | In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS. | ||
| CVE-2020-10242 | Med | 0.40 | 6.1 | 0.01 | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks. | ||
| CVE-2020-8421 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs. | ||
| CVE-2019-16725 | Med | 0.40 | 6.1 | 0.01 | Sep 24, 2019 | In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. | ||
| CVE-2019-12766 | Med | 0.40 | 6.1 | 0.01 | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors. | ||
| CVE-2019-11809 | Med | 0.40 | 6.1 | 0.01 | May 20, 2019 | An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector. |
- risk 0.40cvss 6.1epss 0.00
Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter…
- risk 0.40cvss 6.1epss 0.00
Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers…
- risk 0.40cvss 7.2epss 0.00
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
- risk 0.40cvss 7.3epss 0.00
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
- risk 0.40cvss 6.1epss 0.00
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
- risk 0.40cvss 6.1epss 0.00
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
- risk 0.40cvss 6.1epss 0.00
A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code…
- risk 0.40cvss 6.1epss 0.00
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
- risk 0.40cvss 6.1epss 0.00
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
- risk 0.40cvss 6.1epss 0.00
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
- risk 0.40cvss 6.1epss 0.00
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
- risk 0.40cvss 6.1epss 0.00
The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
- risk 0.40cvss 6.1epss 0.00
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
- risk 0.40cvss 6.1epss 0.00
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
- risk 0.40cvss 6.1epss 0.00
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
- risk 0.40cvss 6.1epss 0.01
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
- risk 0.40cvss 6.1epss 0.00
XSS vulnerability in DP Calendar component for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
- risk 0.40cvss 6.1epss 0.00
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
- risk 0.40cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.
- risk 0.40cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.01
In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
- risk 0.40cvss 6.1epss 0.03
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
- risk 0.40cvss 6.1epss 0.01
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
- risk 0.40cvss 6.1epss 0.01
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
- risk 0.40cvss 6.1epss 0.01
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.
Page 9 of 26