cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 6 of 17
CVE-2026-48955P3MEDIUMCVSS 6.5≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48955 [MEDIUM] CWE-284 CVE-2026-48955: An improper access check allows unauthorized users to access workflow stage and transition informati An improper access check allows unauthorized users to access workflow stage and transition information.
nvd
CVE-2026-90906P3HIGHCVSS 8.3≥ 1.5.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90906 [HIGH] CWE-79 CVE-2026-90906: Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper.
nvd
CVE-2010-4166P3HIGHCVSS 7.5v1.5.0v1.5.1+20 more2011-01-18
CVE-2010-4166 [HIGH] CWE-89 CVE-2010-4166: Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to exec Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_order parameter in a com_weblinks category action to index.php, (2) the filter_order_Dir parameter in a com_weblinks category action to index.php, or (3) the filter_order_Dir parameter in a com_messages action
nvd
CVE-2019-10946P3HIGHCVSS 7.5≥ 3.2.0, ≤ 3.9.42019-04-10
CVE-2019-10946 [HIGH] CWE-306 CVE-2019-10946: An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_use An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.
nvd
CVE-2026-71574P3MEDIUMCVSS 6.5≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-08-18
CVE-2026-71574 [MEDIUM] CWE-284 CVE-2026-71574: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0. Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
nvd
CVE-2015-8564P3HIGHCVSS 7.5v3.4.0v3.4.1+3 more2015-12-16
CVE-2015-8564 [HIGH] CWE-20 CVE-2015-8564: Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unsp Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive.
nvd
CVE-2012-2747P3HIGHCVSS 7.5v2.5.0v2.5.1+3 more2012-07-03
CVE-2012-2747 [HIGH] CVE-2012-2747: Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges v Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."
nvd
CVE-2007-4188P3CRITICALCVSS 9.3fixed in 1.0.132007-08-08
CVE-2007-4188 [CRITICAL] CWE-384 CVE-2007-4188: Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hij Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
nvd
CVE-2016-9837P3HIGHCVSS 7.5≤ 3.6.42016-12-16
CVE-2016-9837 [HIGH] CWE-264 CVE-2016-9837: An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3. An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 reques
nvd
CVE-2010-1432P3HIGHCVSS 7.5≥ 1.5.0, ≤ 1.5.15vJoomla core from 1.5.0 up to and including 1.5.152021-06-21
CVE-2010-1432 [HIGH] CWE-200 CVE-2010-1432: Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue t Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
nvd
CVE-2012-1562P3HIGHCVSS 7.5fixed in 2.5.32020-01-15
CVE-2012-1562 [HIGH] CWE-330 CVE-2012-1562: Joomla! core before 2.5.3 allows unauthorized password change. Joomla! core before 2.5.3 allows unauthorized password change.
nvd
CVE-2023-40626P3HIGHCVSS 7.5≥ 1.6.0, < 3.10.14≥ 4.0.0, < 4.4.1+1 more2023-11-29
CVE-2023-40626 [HIGH] CVE-2023-40626: The language file parsing process could be manipulated to expose environment variables. Environment The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
nvd
CVE-2026-90915P3MEDIUMCVSS 6.5≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90915 [MEDIUM] CWE-22 CVE-2026-90915: Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0 Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.
nvd
CVE-2018-15881P3HIGHCVSS 7.5fixed in 3.8.122018-08-29
CVE-2018-15881 [HIGH] CVE-2018-15881: An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can le An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violation.
nvd
CVE-2021-23131P3HIGHCVSS 7.5≥ 3.2.0, < 3.9.252021-03-04
CVE-2021-23131 [HIGH] CWE-20 CVE-2021-23131: An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the templat An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
nvd
CVE-2020-35611P3HIGHCVSS 7.5≥ 2.5.0, ≤ 3.9.222020-12-28
CVE-2020-35611 [HIGH] CWE-200 CVE-2020-35611: An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not rem An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
nvd
CVE-2020-13763P3HIGHCVSS 7.5≥ 2.5.1, < 3.9.19v2.5.02020-06-02
CVE-2020-13763 [HIGH] CWE-281 CVE-2020-13763: In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block H In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
nvd
CVE-2010-4696P3HIGHCVSS 7.5v1.5.0v1.5.1+20 more2011-01-18
CVE-2010-4696 [HIGH] CVE-2010-4696: Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to exec Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via the (1) filter_order or (2) filter_order_Dir parameter in a com_contact action to index.php, a different vulnerability than CVE-2010-4166. NOTE: the provenance of this information is unknown; the details are obtained solely from thi
nvd
CVE-2021-26038P3HIGHCVSS 7.5≥ 2.5.0, ≤ 3.9.272021-07-07
CVE-2021-26038 [HIGH] CWE-754 CVE-2021-26038: An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the re An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
nvd
CVE-2023-23755P3HIGHCVSS 7.5≥ 4.2.0, < 4.3.22023-05-30
CVE-2023-23755 [HIGH] CWE-307 CVE-2023-23755: An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute forc An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
nvd
Joomla ! vulnerabilities | cvebase