VYPR

Vendor CVEs

Joomla

All CVEs

1,291 total · sorted by risk
  • CVE-2023-54361MedApr 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter…

  • CVE-2023-54360MedApr 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers…

  • CVE-2026-23898HigApr 1, 2026
    risk 0.40cvss 7.2epss 0.00

    Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

  • CVE-2026-21629HigApr 1, 2026
    risk 0.40cvss 7.3epss 0.00

    The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.

  • CVE-2025-63083MedJan 6, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of output escaping leads to a XSS vector in the pagebreak plugin.

  • CVE-2025-63082MedJan 6, 2026
    risk 0.40cvss 6.1epss 0.00

    Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

  • CVE-2025-30084MedJun 5, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code…

  • CVE-2024-40743MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

  • CVE-2024-27186MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

  • CVE-2024-27184MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

  • CVE-2024-27183MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    XSS vulnerability in DJ-HelpfulArticles component for Joomla.

  • CVE-2024-26279MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    The wrapper extensions do not correctly validate inputs, leading to XSS vectors.

  • CVE-2024-26278MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    The Custom Fields component not correctly filter inputs, leading to a XSS vector.

  • CVE-2024-21731MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.

  • CVE-2024-21729MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

  • CVE-2024-21724MedFeb 29, 2024
    risk 0.40cvss 6.1epss 0.01

    Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.

  • CVE-2024-21727MedFeb 15, 2024
    risk 0.40cvss 6.1epss 0.00

    XSS vulnerability in DP Calendar component for Joomla.

  • CVE-2023-40659MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.

  • CVE-2023-40658MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.

  • CVE-2023-40657MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.

  • CVE-2023-40656MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the Quickform component for Joomla.

  • CVE-2023-40655MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.

  • CVE-2023-40628MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

  • CVE-2023-40627MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.

  • CVE-2023-39971MedAug 17, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

  • CVE-2023-38045MedAug 7, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

  • CVE-2023-23754MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

  • CVE-2022-27914MedNov 8, 2022
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.

  • CVE-2022-27913MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

  • CVE-2022-27910MedJul 10, 2022
    risk 0.40cvss 6.1epss 0.01

    In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function

  • CVE-2022-23801MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.

  • CVE-2022-23800MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.

  • CVE-2022-23798MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.

  • CVE-2022-23796MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.

  • CVE-2021-26039MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.

  • CVE-2021-26035MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

  • CVE-2021-26032MedMay 26, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.

  • CVE-2021-23130MedMar 4, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.

  • CVE-2021-23129MedMar 4, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.

  • CVE-2021-23125MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.

  • CVE-2020-24599MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.

  • CVE-2020-24598MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

  • CVE-2020-15696MedJul 15, 2020
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.

  • CVE-2020-13762MedJun 2, 2020
    risk 0.40cvss 6.1epss 0.01

    In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.

  • CVE-2020-13761MedJun 2, 2020
    risk 0.40cvss 6.1epss 0.01

    In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.

  • CVE-2020-10242MedMar 16, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.

  • CVE-2020-8421MedJan 28, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.

  • CVE-2019-16725MedSep 24, 2019
    risk 0.40cvss 6.1epss 0.01

    In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.

  • CVE-2019-12766MedJun 11, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.

  • CVE-2019-11809MedMay 20, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.

Page 9 of 26