cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 11 of 17
CVE-2024-21724P4MEDIUMCVSS 6.1≥ 1.6.0, < 3.10.15≥ 4.0.0, < 4.4.3+1 more2024-02-29
CVE-2024-21724 [MEDIUM] CWE-79 CVE-2024-21724: Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extens Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
nvd
CVE-2024-21729P4MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.6≥ 5.0.0, < 5.1.22024-07-09
CVE-2024-21729 [MEDIUM] CWE-79 CVE-2024-21729: Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
nvd
CVE-2026-48903P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-48903 [MEDIUM] CWE-79 CVE-2026-48903: Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in vario Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
nvd
CVE-2026-30895P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-30895 [MEDIUM] CWE-79 CVE-2026-30895: Lack of output escaping leads to a XSS vector in the readmore links for com_content. Lack of output escaping leads to a XSS vector in the readmore links for com_content.
nvd
CVE-2020-10240P4MEDIUMCVSS 5.3≥ 3.0.0, < 3.9.162020-03-16
CVE-2020-10240 [MEDIUM] CWE-20 CVE-2020-10240: An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead t An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
nvd
CVE-2018-15880P4MEDIUMCVSS 5.4fixed in 3.8.122018-08-29
CVE-2018-15880 [MEDIUM] CWE-79 CVE-2018-15880: An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile pa An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.
nvd
CVE-2021-23123P4MEDIUMCVSS 5.3≥ 3.0.0, ≤ 3.9.232021-01-12
CVE-2021-23123 [MEDIUM] CWE-862 CVE-2021-23123: An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
nvd
CVE-2020-35614P4MEDIUMCVSS 5.3≥ 3.9.0, ≤ 3.9.222020-12-28
CVE-2020-35614 [MEDIUM] CVE-2020-35614: An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
nvd
CVE-2021-26037P4MEDIUMCVSS 5.3≥ 2.5.0, ≤ 3.9.272021-07-07
CVE-2021-26037 [MEDIUM] CWE-613 CVE-2021-26037: An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine exis An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
nvd
CVE-2022-27911P4MEDIUMCVSS 5.3v4.2.02022-08-31
CVE-2022-27911 [MEDIUM] CVE-2022-27911: An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.
nvd
CVE-2011-4321P4MEDIUMCVSS 5.0v1.5.0v1.5.1+23 more2011-11-23
CVE-2011-4321 [MEDIUM] CWE-310 CVE-2011-4321: The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which mak The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecified vectors.
nvd
CVE-2018-6378P4MEDIUMCVSS 6.1fixed in 3.8.82018-05-22
CVE-2018-6378 [MEDIUM] CWE-79 CVE-2018-6378: In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS att In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
nvd
CVE-2020-8421P4MEDIUMCVSS 6.1≥ 3.9.0, < 3.9.142020-01-28
CVE-2020-8421 [MEDIUM] CWE-79 CVE-2020-8421: An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attack An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
nvd
CVE-2020-10242P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.9.162020-03-16
CVE-2020-10242 [MEDIUM] CWE-79 CVE-2020-10242: An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protos An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
nvd
CVE-2020-24599P4MEDIUMCVSS 6.1≥ 3.9.0, < 3.9.212020-08-26
CVE-2020-24599 [MEDIUM] CWE-79 CVE-2020-24599: An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS a An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
nvd
CVE-2020-13761P4MEDIUMCVSS 6.1≥ 3.0.1, < 3.9.19v3.0.02020-06-02
CVE-2020-13761 [MEDIUM] CWE-79 CVE-2020-13761: In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - News In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
nvd
CVE-2020-13762P4MEDIUMCVSS 6.1≥ 3.9.0, < 3.9.192020-06-02
CVE-2020-13762 [MEDIUM] CWE-79 CVE-2020-13762: In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
nvd
CVE-2019-12766P4MEDIUMCVSS 6.1≥ 3.6.0, ≤ 3.9.62019-06-11
CVE-2019-12766 [MEDIUM] CWE-79 CVE-2019-12766: An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.
nvd
CVE-2021-23130P4MEDIUMCVSS 6.1≥ 2.5.0, < 3.9.252021-03-04
CVE-2021-23130 [MEDIUM] CWE-79 CVE-2021-23130: An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.
nvd
CVE-2021-23129P4MEDIUMCVSS 6.1≥ 2.5.0, < 3.9.252021-03-04
CVE-2021-23129 [MEDIUM] CWE-79 CVE-2021-23129: An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to use An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.
nvd
Joomla ! vulnerabilities | cvebase