cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 14 of 17
CVE-2019-9714P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.9.42019-03-12
CVE-2019-9714 [MEDIUM] CWE-79 CVE-2019-9714: An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
nvd
CVE-2019-9711P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.9.42019-03-12
CVE-2019-9711 [MEDIUM] CWE-79 CVE-2019-9711: An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
nvd
CVE-2024-26279P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.10.16≥ 4.0.0, < 4.4.6+1 more2024-07-09
CVE-2024-26279 [MEDIUM] CWE-79 CVE-2024-26279: The wrapper extensions do not correctly validate inputs, leading to XSS vectors. The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
nvd
CVE-2023-23754P4MEDIUMCVSS 6.1≥ 4.2.0, < 4.3.22023-05-30
CVE-2023-23754 [MEDIUM] CWE-20 CVE-2023-23754: An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redi An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
nvd
CVE-2024-27186P4MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.7≥ 5.0.0, < 5.1.32024-08-20
CVE-2024-27186 [MEDIUM] CWE-79 CVE-2024-27186: The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
nvd
CVE-2021-26028P4MEDIUMCVSS 5.5≥ 3.0.0, < 3.9.252021-03-04
CVE-2021-26028 [MEDIUM] CWE-22 CVE-2021-26028: An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip packag An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
nvd
CVE-2012-0819P4MEDIUMCVSS 5.0v1.6v1.6.0+9 more2012-09-06
CVE-2012-0819 [MEDIUM] CVE-2012-0819: Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0821.
nvd
CVE-2012-0821P4MEDIUMCVSS 5.0v1.6v1.6.0+9 more2012-09-06
CVE-2012-0821 [MEDIUM] CVE-2012-0821: Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0819.
nvd
CVE-2011-3595P4MEDIUMCVSS 5.4≤ 1.7.02020-01-22
CVE-2011-3595 [MEDIUM] CWE-79 CVE-2011-3595: Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in t Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
nvd
CVE-2012-0837P4MEDIUMCVSS 5.0v1.7.0v1.7.1+4 more2012-09-06
CVE-2012-0837 [MEDIUM] CWE-200 CVE-2012-0837: Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path v Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."
nvd
CVE-2013-3056P4MEDIUMCVSS 4.0v2.5.0v2.5.1+12 more2013-05-03
CVE-2013-3056 [MEDIUM] CWE-264 CVE-2013-3056: Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass inten Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and delete the private messages of arbitrary users via unspecified vectors.
nvd
CVE-2013-3057P4MEDIUMCVSS 4.0v2.5.0v2.5.1+12 more2013-05-03
CVE-2013-3057 [MEDIUM] CWE-264 CVE-2013-3057: Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass inten Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and list the privileges of arbitrary users via unspecified vectors.
nvd
CVE-2026-73372P4MEDIUMCVSS 4.3≥ 5.1.0, < 5.4.8≥ 6.0.0, < 6.1.32026-08-18
CVE-2026-73372 [MEDIUM] CWE-284 CVE-2026-73372: Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
nvd
CVE-2012-2748P4MEDIUMCVSS 5.0v2.5.0v2.5.1+3 more2012-07-03
CVE-2012-2748 [MEDIUM] CVE-2012-2748: Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate filtering" and a "SQL error."
nvd
CVE-2018-11328P4MEDIUMCVSS 4.7fixed in 3.8.82018-05-22
CVE-2018-11328 [MEDIUM] CWE-79 CVE-2018-11328: An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issue An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.
nvd
CVE-2017-16633P4MEDIUMCVSS 4.3≥ 3.7.0, ≤ 3.8.12017-11-10
CVE-2017-16633 [MEDIUM] CWE-200 CVE-2017-16633: In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's cust In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
nvd
CVE-2026-48900P4MEDIUMCVSS 4.3≥ 4.1.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-48900 [MEDIUM] CWE-284 CVE-2026-48900: An improper access check allowed low privileged users to edit the task types of existing scheduler t An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
nvd
CVE-2015-5608P4MEDIUMCVSS 6.1v3.0.0v3.0.1+26 more2017-09-20
CVE-2015-5608 [MEDIUM] CWE-601 CVE-2015-5608: Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1. Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
nvd
CVE-2017-8057P4MEDIUMCVSS 5.3v3.4.0v3.4.1+15 more2017-04-25
CVE-2017-8057 [MEDIUM] CWE-200 CVE-2017-8057: In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on syst In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
nvd
CVE-2011-2488P4MEDIUMCVSS 5.0≤ 1.5.22v1.5.0+21 more2011-07-27
CVE-2011-2488 [MEDIUM] CWE-200 CVE-2011-2488: Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain se Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
Joomla ! vulnerabilities | cvebase