cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 12 of 17
CVE-2019-7741P4MEDIUMCVSS 6.1≥ 2.5.0, ≤ 3.9.22019-02-12
CVE-2019-7741 [MEDIUM] CWE-79 CVE-2019-7741: An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpu An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
nvd
CVE-2019-7740P4MEDIUMCVSS 6.1≥ 2.5.0, ≤ 3.9.22019-02-12
CVE-2019-7740 [MEDIUM] CWE-79 CVE-2019-7740: An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (c An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
nvd
CVE-2017-7987P4MEDIUMCVSS 6.1v3.2.0v3.2.1+26 more2017-04-25
CVE-2017-7987 [MEDIUM] CWE-79 CVE-2017-7987: In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
nvd
CVE-2017-7984P4MEDIUMCVSS 6.1v3.2.0v3.2.1+26 more2017-04-25
CVE-2017-7984 [MEDIUM] CWE-79 CVE-2017-7984: In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template m In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
nvd
CVE-2019-16725P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.9.122019-09-24
CVE-2019-16725 [MEDIUM] CWE-79 CVE-2019-16725: In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of th In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
nvd
CVE-2022-23801P4MEDIUMCVSS 6.1≥ 4.0.0, ≤ 4.1.02022-03-30
CVE-2022-23801 [MEDIUM] CWE-79 CVE-2022-23801: An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedd An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
nvd
CVE-2024-21731P4MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.10.15≥ 4.0.0, ≤ 4.4.5+1 more2024-07-09
CVE-2024-21731 [MEDIUM] CWE-79 CVE-2024-21731: Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
nvd
CVE-2024-27184P4MEDIUMCVSS 6.1≥ 3.4.6, < 3.10.17≥ 4.0.0, < 4.4.7+1 more2024-08-20
CVE-2024-27184 [MEDIUM] CWE-601 CVE-2024-27184: Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
nvd
CVE-2024-40747P4MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.10≥ 5.0.0, < 5.2.32025-01-07
CVE-2024-40747 [MEDIUM] CWE-79 CVE-2024-40747: Various module chromes didn't properly process inputs, leading to XSS vectors. Various module chromes didn't properly process inputs, leading to XSS vectors.
nvd
CVE-2009-3945P4MEDIUMCVSS 5.5≤ 1.5.14v1.5.0+13 more2009-11-16
CVE-2009-3945 [MEDIUM] CVE-2009-3945: Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5 Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.
nvd
CVE-2015-7859P4MEDIUMCVSS 5.0v3.2.0v3.2.1+13 more2015-10-29
CVE-2015-7859 [MEDIUM] CWE-200 CVE-2015-7859: The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which all The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2015-7899P4MEDIUMCVSS 5.0v3.2.0v3.2.1+13 more2015-10-29
CVE-2015-7899 [MEDIUM] CWE-284 CVE-2015-7899: The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows rem The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2021-23126P4MEDIUMCVSS 5.3≥ 3.2.0, < 3.9.252021-03-04
CVE-2021-23126 [MEDIUM] CWE-338 CVE-2021-23126: An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function withi An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
nvd
CVE-2021-26031P4MEDIUMCVSS 5.3≥ 3.0.0, ≤ 3.9.252021-04-14
CVE-2021-26031 [MEDIUM] CVE-2021-26031: An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout setting An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.
nvd
CVE-2019-15028P4MEDIUMCVSS 5.3≥ 1.6.2, < 3.9.112019-08-14
CVE-2019-15028 [MEDIUM] CVE-2019-15028: In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled f In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
nvd
CVE-2021-26027P4MEDIUMCVSS 5.3≥ 3.0.0, < 3.9.252021-03-04
CVE-2021-26027 [MEDIUM] CWE-863 CVE-2021-26027: An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthoriz An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
nvd
CVE-2019-6262P4MEDIUMCVSS 5.4≥ 2.5.0, < 3.9.22019-01-16
CVE-2019-6262 [MEDIUM] CWE-79 CVE-2019-6262: An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpu An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.
nvd
CVE-2011-4912P4MEDIUMCVSS 5.3≥ 1.5.0, ≤ 1.5.132020-02-04
CVE-2011-4912 [MEDIUM] CWE-732 CVE-2011-4912: Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
nvd
CVE-2011-4911P4MEDIUMCVSS 5.0≤ 1.5.11v1.5.0+10 more2012-10-07
CVE-2011-4911 [MEDIUM] CWE-20 CVE-2011-4911: Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attac Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.
nvd
CVE-2020-15699P4MEDIUMCVSS 5.3≥ 2.5.0, ≤ 3.9.192020-07-15
CVE-2020-15699 [MEDIUM] CWE-345 CVE-2020-15699: An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
nvd
Joomla ! vulnerabilities | cvebase