Joomla ! vulnerabilities
334 known vulnerabilities affecting joomla/joomla_!.
Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4
Vulnerabilities
Page 5 of 17
CVE-2020-35616P3HIGHCVSS 7.5≥ 1.7.0, ≤ 3.9.222020-12-28
CVE-2020-35616 [HIGH] CWE-20 CVE-2020-35616: An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.
nvd
CVE-2021-23128P3CRITICALCVSS 9.1≥ 3.2.0, < 3.9.252021-03-04
CVE-2021-23128 [CRITICAL] CVE-2021-23128: An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval impleme
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.
nvd
CVE-2018-11322P3HIGHCVSS 7.5fixed in 3.8.82018-05-22
CVE-2018-11322 [HIGH] CWE-434 CVE-2018-11322: An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR fi
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
nvd
CVE-2024-40749P3HIGHCVSS 7.5≥ 3.9.0, < 3.10.20≥ 4.0.0, < 4.4.10+1 more2025-01-07
CVE-2024-40749 [HIGH] CWE-284 CVE-2024-40749: Improper Access Controls allows access to protected views.
Improper Access Controls allows access to protected views.
nvd
CVE-2021-23127P3CRITICALCVSS 9.1≥ 3.2.0, < 3.9.252021-03-04
CVE-2021-23127 [CRITICAL] CVE-2021-23127: An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.
nvd
CVE-2020-10238P3HIGHCVSS 7.5≥ 2.5.0, < 3.9.162020-03-16
CVE-2020-10238 [HIGH] CWE-668 CVE-2020-10238: An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.
nvd
CVE-2022-23793P3HIGHCVSS 7.5≥ 3.0.0, ≤ 3.10.6≥ 4.0.0, ≤ 4.1.02022-03-30
CVE-2022-23793 [HIGH] CWE-22 CVE-2022-23793: An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifi
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
nvd
CVE-2010-1434P3HIGHCVSS 7.5≥ 1.5.0, ≤ 1.5.15vJoomla core from 1.5.0 up to and including 1.5.152021-06-21
CVE-2010-1434 [HIGH] CWE-384 CVE-2010-1434: Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hi
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
nvd
CVE-2026-48901P3HIGHCVSS 7.5≥ 4.0.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-48901 [HIGH] CWE-524 CVE-2026-48901: The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
nvd
CVE-2024-27187P3HIGHCVSS 7.5≥ 4.0.0, < 4.4.7≥ 5.0.0, < 5.1.32024-08-20
CVE-2024-27187 [HIGH] CWE-284 CVE-2024-27187: Improper Access Controls allows backend users to overwrite their username when disallowed.
Improper Access Controls allows backend users to overwrite their username when disallowed.
nvd
CVE-2024-21725P3MEDIUMCVSS 6.1≥ 4.0.0, < 4.4.3≥ 5.0.0, < 5.0.32024-02-29
CVE-2024-21725 [MEDIUM] CWE-79 CVE-2024-21725: Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
nvd
CVE-2020-35612P3HIGHCVSS 7.5≥ 2.5.0, ≤ 3.9.222020-12-28
CVE-2020-35612 [HIGH] CWE-22 CVE-2020-35612: An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image la
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
nvd
CVE-2025-25227P3HIGHCVSS 7.5≥ 4.0.0, < 4.4.13≥ 5.0.0, < 5.2.62025-04-08
CVE-2025-25227 [HIGH] CWE-287 CVE-2025-25227: Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
nvd
CVE-2026-21629P3HIGHCVSS 7.3≥ 3.0.0, < 5.4.4≥ 6.0.0, < 6.0.42026-04-01
CVE-2026-21629 [HIGH] CWE-284 CVE-2026-21629: The ajax component was excluded from the default logged-in-user check in the administrative area. Th
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
nvd
CVE-2011-4909P4MEDIUMCVSS 4.3PoC≤ 1.5.11v1.5.0+10 more2012-10-07
CVE-2011-4909 [MEDIUM] CWE-79 CVE-2011-4909: Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.p
nvd
CVE-2015-8565P3HIGHCVSS 7.5v3.2.0v3.2.1+14 more2015-12-16
CVE-2015-8565 [HIGH] CWE-20 CVE-2015-8565: Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remot
Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2019-9713P3HIGHCVSS 7.5≥ 3.8.0, < 3.9.42019-03-12
CVE-2019-9713 [HIGH] CWE-862 CVE-2019-9713: An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing u
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
nvd
CVE-2026-92222P3HIGHCVSS 8.0≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-92222 [HIGH] CWE-918 CVE-2026-92222: Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.
Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.
nvd
CVE-2020-35610P3HIGHCVSS 7.5≥ 2.5.0, ≤ 3.9.222020-12-28
CVE-2020-35610 [HIGH] CVE-2020-35610: An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder di
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
nvd
CVE-2020-13760P3HIGHCVSS 8.8≥ 3.7.1, < 3.9.19v3.7.02020-06-02
CVE-2020-13760 [HIGH] CWE-352 CVE-2020-13760: In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
nvd