cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 13 of 17
CVE-2022-27912P4MEDIUMCVSS 5.3≥ 4.0.0, ≤ 4.2.32022-10-25
CVE-2022-27912 [MEDIUM] CWE-200 CVE-2022-27912: An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode expos An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
nvd
CVE-2026-21632P4MEDIUMCVSS 5.4≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21632 [MEDIUM] CWE-79 CVE-2026-21632: Lack of output escaping for article titles leads to XSS vectors in various locations. Lack of output escaping for article titles leads to XSS vectors in various locations.
nvd
CVE-2026-73371P4MEDIUMCVSS 4.3≥ 4.0.0, ≤ 5.4.8≥ 6.0.0, ≤ 6.1.32026-08-18
CVE-2026-73371 [MEDIUM] CWE-284 CVE-2026-73371: Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0- Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
nvd
CVE-2017-7985P4MEDIUMCVSS 6.1≥ 1.5.0, ≤ 3.6.52017-04-25
CVE-2017-7985 [MEDIUM] CWE-79 CVE-2017-7985: In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
nvd
CVE-2021-26032P4MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.9.262021-05-26
CVE-2021-26032 [MEDIUM] CWE-79 CVE-2021-26032: An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block li An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
nvd
CVE-2019-7744P4MEDIUMCVSS 6.1≥ 2.5.0, ≤ 3.9.22019-02-12
CVE-2019-7744 [MEDIUM] CWE-79 CVE-2019-7744: An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.
nvd
CVE-2021-23125P4MEDIUMCVSS 6.1≥ 3.1.0, ≤ 3.9.232021-01-12
CVE-2021-23125 [MEDIUM] CWE-79 CVE-2021-23125: An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related param An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
nvd
CVE-2019-9712P4MEDIUMCVSS 6.1≥ 3.2.0, < 3.9.42019-03-12
CVE-2019-9712 [MEDIUM] CWE-79 CVE-2019-9712: An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validati An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
nvd
CVE-2022-23800P4MEDIUMCVSS 6.1≥ 4.0.0, ≤ 4.1.02022-03-30
CVE-2022-23800 [MEDIUM] CWE-79 CVE-2022-23800: An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vu An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
nvd
CVE-2022-27914P4MEDIUMCVSS 6.1≥ 4.0.0, < 4.2.52022-11-08
CVE-2022-27914 [MEDIUM] CWE-79 CVE-2022-27914: An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially maliciou An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
nvd
CVE-2024-26278P4MEDIUMCVSS 6.1≥ 3.7.0, < 3.10.16≥ 4.0.0, < 4.4.6+1 more2024-07-09
CVE-2024-26278 [MEDIUM] CWE-79 CVE-2024-26278: The Custom Fields component not correctly filter inputs, leading to a XSS vector. The Custom Fields component not correctly filter inputs, leading to a XSS vector.
nvd
CVE-2022-27913P4MEDIUMCVSS 6.1≥ 4.0.0, ≤ 4.2.32022-10-25
CVE-2022-27913 [MEDIUM] CWE-79 CVE-2022-27913: An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially maliciou An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
nvd
CVE-2024-40743P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.10.17≥ 4.0.0, < 4.4.6+1 more2024-08-20
CVE-2024-40743 [MEDIUM] CWE-79 CVE-2024-40743: The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
nvd
CVE-2017-7983P4MEDIUMCVSS 5.3v1.5.0v1.5.1+105 more2017-04-25
CVE-2017-7983 [MEDIUM] CWE-200 CVE-2017-7983: In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMa In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
nvd
CVE-2021-26029P4MEDIUMCVSS 5.3≥ 1.6.0, < 3.9.252021-03-04
CVE-2021-26029 [MEDIUM] CVE-2021-26029: An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.
nvd
CVE-2017-7988P4MEDIUMCVSS 5.3v1.5.16v1.5.17+89 more2017-04-25
CVE-2017-7988 [MEDIUM] CVE-2017-7988: In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwr In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
nvd
CVE-2022-23794P4MEDIUMCVSS 5.3≥ 3.0.0, ≤ 3.10.6≥ 4.0.0, ≤ 4.1.02022-03-30
CVE-2022-23794 [MEDIUM] CWE-209 CVE-2022-23794: An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
nvd
CVE-2024-21730P4MEDIUMCVSS 5.4≥ 4.0.0, < 4.4.6≥ 5.0.0, < 5.1.22024-07-09
CVE-2024-21730 [MEDIUM] CWE-79 CVE-2024-21730: The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
nvd
CVE-2017-11612P4MEDIUMCVSS 6.1v1.5.0v1.5.1+112 more2017-07-26
CVE-2017-11612 [MEDIUM] CWE-79 CVE-2017-11612: In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulner In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
nvd
CVE-2017-7986P4MEDIUMCVSS 6.1v1.5.0v1.5.1+105 more2017-04-25
CVE-2017-7986 [MEDIUM] CWE-79 CVE-2017-7986: In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes le In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
nvd
Joomla ! vulnerabilities | cvebase