Joomla ! vulnerabilities
276 known vulnerabilities affecting joomla/joomla_!.
Total CVEs
276
CISA KEV
2
actively exploited
Public exploits
22
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH68MEDIUM176LOW2
Vulnerabilities
Page 1 of 14
CVE-2026-23899HIGHCVSS 8.6≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-23899 [HIGH] CWE-284 CVE-2026-23899: An improper access check allows unauthorized access to webservice endpoints.
An improper access check allows unauthorized access to webservice endpoints.
nvd
CVE-2026-23898HIGHCVSS 8.6≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-23898 [HIGH] CWE-73 CVE-2026-23898: Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
nvd
CVE-2026-21632MEDIUMCVSS 5.9≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21632 [MEDIUM] CWE-79 CVE-2026-21632: Lack of output escaping for article titles leads to XSS vectors in various locations.
Lack of output escaping for article titles leads to XSS vectors in various locations.
nvd
CVE-2026-21630MEDIUMCVSS 6.9≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21630 [MEDIUM] CWE-89 CVE-2026-21630: Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endp
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
nvd
CVE-2026-21631MEDIUMCVSS 5.9≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21631 [MEDIUM] CWE-79 CVE-2026-21631: Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
nvd
CVE-2026-21629MEDIUMCVSS 6.3≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21629 [MEDIUM] CWE-284 CVE-2026-21629: The ajax component was excluded from the default logged-in-user check in the administrative area. Th
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
nvd
CVE-2025-63083MEDIUMCVSS 5.9≥ 3.9.0, < 5.4.2≥ 6.0.0, < 6.0.22026-01-06
CVE-2025-63083 [MEDIUM] CWE-79 CVE-2025-63083: Lack of output escaping leads to a XSS vector in the pagebreak plugin.
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
nvd
CVE-2025-63082MEDIUMCVSS 5.9≥ 4.0.0, < 5.4.2≥ 6.0.0, < 6.0.22026-01-06
CVE-2025-63082 [MEDIUM] CWE-79 CVE-2025-63082: Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img t
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
nvd
CVE-2025-25226CRITICALCVSS 9.8≥ 1.0.0, < 2.2.0≥ 3.0.0, < 3.4.02025-04-08
CVE-2025-25226 [CRITICAL] CWE-89 CVE-2025-25226: Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original databa
nvd
CVE-2025-25227HIGHCVSS 7.5≥ 4.0.0, < 4.4.13≥ 5.0.0, < 5.2.62025-04-08
CVE-2025-25227 [HIGH] CWE-287 CVE-2025-25227: Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
nvd
CVE-2024-40749HIGHCVSS 7.5≥ 3.9.0, < 3.10.20≥ 4.0.0, < 4.4.10+1 more2025-01-07
CVE-2024-40749 [HIGH] CWE-284 CVE-2024-40749: Improper Access Controls allows access to protected views.
Improper Access Controls allows access to protected views.
nvd
CVE-2024-40748HIGHCVSS 7.5≥ 3.9.0, < 3.10.20≥ 4.0.0, < 4.4.10+1 more2025-01-07
CVE-2024-40748 [HIGH] CWE-79 CVE-2024-40748: Lack of output escaping in the id attribute of menu lists.
Lack of output escaping in the id attribute of menu lists.
nvd
CVE-2024-40747MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.10≥ 5.0.0, < 5.2.32025-01-07
CVE-2024-40747 [MEDIUM] CWE-79 CVE-2024-40747: Various module chromes didn't properly process inputs, leading to XSS vectors.
Various module chromes didn't properly process inputs, leading to XSS vectors.
nvd
CVE-2024-27185CRITICALCVSS 9.1≥ 3.0.0, < 3.10.17≥ 4.0.0, < 4.4.7+1 more2024-08-20
CVE-2024-27185 [CRITICAL] CWE-444 CVE-2024-27185: The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vecto
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
nvd
CVE-2024-27187HIGHCVSS 7.5≥ 4.0.0, < 4.4.7≥ 5.0.0, < 5.1.32024-08-20
CVE-2024-27187 [HIGH] CWE-284 CVE-2024-27187: Improper Access Controls allows backend users to overwrite their username when disallowed.
Improper Access Controls allows backend users to overwrite their username when disallowed.
nvd
CVE-2024-27186MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.7≥ 5.0.0, < 5.1.32024-08-20
CVE-2024-27186 [MEDIUM] CWE-79 CVE-2024-27186: The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
nvd
CVE-2024-27184MEDIUMCVSS 6.1≥ 3.4.6, < 3.10.17≥ 4.0.0, < 4.4.7+1 more2024-08-20
CVE-2024-27184 [MEDIUM] CWE-601 CVE-2024-27184: Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
nvd
CVE-2024-40743MEDIUMCVSS 6.1≥ 3.0.0, < 3.10.17≥ 4.0.0, < 4.4.6+1 more2024-08-20
CVE-2024-40743 [MEDIUM] CWE-79 CVE-2024-40743: The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
nvd
CVE-2024-21729MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.6≥ 5.0.0, < 5.1.22024-07-09
CVE-2024-21729 [MEDIUM] CWE-79 CVE-2024-21729: Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
nvd
CVE-2024-21731MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.10.15≥ 4.0.0, ≤ 4.4.5+1 more2024-07-09
CVE-2024-21731 [MEDIUM] CWE-79 CVE-2024-21731: Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
nvd
1 / 14Next →