Joomla ! vulnerabilities
334 known vulnerabilities affecting joomla/joomla_!.
Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4
Vulnerabilities
Page 10 of 17
CVE-2026-25901P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-25901 [MEDIUM] CWE-79 CVE-2026-25901: Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
nvd
CVE-2026-30894P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-30894 [MEDIUM] CWE-79 CVE-2026-30894: Lack of output escaping leads to a XSS vector in the content history component.
Lack of output escaping leads to a XSS vector in the content history component.
nvd
CVE-2025-63083P4MEDIUMCVSS 6.1≥ 3.9.0, < 5.4.2≥ 6.0.0, < 6.0.22026-01-06
CVE-2025-63083 [MEDIUM] CWE-79 CVE-2025-63083: Lack of output escaping leads to a XSS vector in the pagebreak plugin.
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
nvd
CVE-2025-63082P4MEDIUMCVSS 6.1≥ 4.0.0, < 5.4.2≥ 6.0.0, < 6.0.22026-01-06
CVE-2025-63082 [MEDIUM] CWE-79 CVE-2025-63082: Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img t
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
nvd
CVE-2020-15698P4MEDIUMCVSS 5.3≥ 3.0.0, ≤ 3.9.192020-07-15
CVE-2020-15698 [MEDIUM] CVE-2020-15698: An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information sc
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
nvd
CVE-2019-19845P4MEDIUMCVSS 5.3≥ 3.8.0, < 3.9.142019-12-18
CVE-2019-19845 [MEDIUM] CWE-22 CVE-2019-19845: In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
nvd
CVE-2019-18674P4MEDIUMCVSS 5.3≥ 3.6.0, < 3.9.132019-11-06
CVE-2019-18674 [MEDIUM] CWE-862 CVE-2019-18674: An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping file
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.
nvd
CVE-2020-11891P4MEDIUMCVSS 5.3≥ 3.8.8, < 3.9.172020-04-21
CVE-2020-11891 [MEDIUM] CVE-2020-11891: An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section o
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
nvd
CVE-2020-11889P4MEDIUMCVSS 5.3≥ 2.5.0, < 3.9.172020-04-21
CVE-2020-11889 [MEDIUM] CVE-2020-11889: An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section o
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
nvd
CVE-2026-21631P4MEDIUMCVSS 5.4≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21631 [MEDIUM] CWE-79 CVE-2026-21631: Lack of output escaping leads to a XSS vector in the multilingual associations component.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
nvd
CVE-2006-4471P4MEDIUMCVSS 6.5fixed in 1.0.112006-08-31
CVE-2006-4471 [MEDIUM] CWE-434 CVE-2006-4471: The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to u
The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.
nvd
CVE-2020-24598P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.9.212020-08-26
CVE-2020-24598 [MEDIUM] CWE-601 CVE-2020-24598: An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of co
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
nvd
CVE-2019-7739P4MEDIUMCVSS 6.1≥ 2.5.0, ≤ 3.9.22019-02-12
CVE-2019-7739 [MEDIUM] CVE-2019-7739: An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child setti
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this.
nvd
CVE-2019-11809P4MEDIUMCVSS 6.1≥ 1.7.0, < 3.9.62019-05-20
CVE-2019-11809 [MEDIUM] CWE-79 CVE-2019-11809: An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.
nvd
CVE-2019-7742P4MEDIUMCVSS 6.1≥ 1.0.0, ≤ 3.9.22019-02-12
CVE-2019-7742 [MEDIUM] CWE-79 CVE-2019-7742: An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.
nvd
CVE-2019-6264P4MEDIUMCVSS 6.1≥ 2.5.0, < 3.9.22019-01-16
CVE-2019-6264 [MEDIUM] CWE-79 CVE-2019-6264: An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a store
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.
nvd
CVE-2019-6261P4MEDIUMCVSS 6.1≥ 2.5.0, < 3.9.22019-01-16
CVE-2019-6261 [MEDIUM] CWE-79 CVE-2019-6261: An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a store
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.
nvd
CVE-2021-26039P4MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.9.272021-07-07
CVE-2021-26039 [MEDIUM] CWE-79 CVE-2021-26039: An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view o
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.
nvd
CVE-2022-23798P4MEDIUMCVSS 6.1≥ 2.5.0, ≤ 3.10.6≥ 4.0.0, ≤ 4.1.02022-03-30
CVE-2022-23798 [MEDIUM] CWE-601 CVE-2022-23798: An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
nvd
CVE-2022-23796P4MEDIUMCVSS 6.1≥ 3.7.0, ≤ 3.10.62022-03-30
CVE-2022-23796 [MEDIUM] CWE-79 CVE-2022-23796: An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
nvd