cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 7 of 17
CVE-2024-40748P3HIGHCVSS 7.5≥ 3.9.0, < 3.10.20≥ 4.0.0, < 4.4.10+1 more2025-01-07
CVE-2024-40748 [HIGH] CWE-79 CVE-2024-40748: Lack of output escaping in the id attribute of menu lists. Lack of output escaping in the id attribute of menu lists.
nvd
CVE-2006-4472P3HIGHCVSS 7.5fixed in 1.0.112006-08-31
CVE-2006-4472 [HIGH] CVE-2006-4472: Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authent Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.
nvd
CVE-2017-9933P3HIGHCVSS 7.5v1.7.3v1.7.4+72 more2017-07-17
CVE-2017-9933 [HIGH] CWE-200 CVE-2017-9933: Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
nvd
CVE-2011-4937P3HIGHCVSS 7.5fixed in 1.7.22020-02-04
CVE-2011-4937 [HIGH] CWE-200 CVE-2011-4937: Joomla! 1.7.1 has core information disclosure due to inadequate error checking. Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
nvd
CVE-2018-17858P3HIGHCVSS 8.8≥ 2.5.0, < 3.8.132018-10-09
CVE-2018-17858 [HIGH] CWE-352 CVE-2018-17858: An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.
nvd
CVE-2020-10241P3HIGHCVSS 8.8≥ 3.2.0, < 3.9.162020-03-16
CVE-2020-10241 [HIGH] CWE-352 CVE-2020-10241: An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_t An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
nvd
CVE-2021-26036P3HIGHCVSS 7.5≥ 2.5.0, ≤ 3.9.272021-07-07
CVE-2021-26036 [HIGH] CWE-20 CVE-2021-26036: An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.
nvd
CVE-2006-4469P3HIGHCVSS 7.5fixed in 1.0.112006-08-31
CVE-2006-4469 [HIGH] CVE-2006-4469: Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "r Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."
nvd
CVE-2026-92231P3MEDIUMCVSS 6.7≥ 1.5.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-92231 [MEDIUM] CWE-79 CVE-2026-92231: Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
nvd
CVE-2026-92225P3MEDIUMCVSS 6.7≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-92225 [MEDIUM] CWE-79 CVE-2026-92225: Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The modul Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.
nvd
CVE-2020-8420P4HIGHCVSS 8.8≥ 3.0.0, < 3.9.152020-01-28
CVE-2020-8420 [HIGH] CWE-352 CVE-2020-8420: An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
nvd
CVE-2026-92232P3MEDIUMCVSS 6.5≥ 1.5.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-92232 [MEDIUM] CWE-79 CVE-2026-92232: Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTM Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.
nvd
CVE-2020-8419P4HIGHCVSS 8.8≥ 3.0.0, < 3.9.152020-01-28
CVE-2020-8419 [HIGH] CWE-352 CVE-2020-8419: An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of vario An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
nvd
CVE-2019-18650P4HIGHCVSS 8.8≥ 3.2.0, ≤ 3.9.122019-11-06
CVE-2019-18650 [HIGH] CWE-352 CVE-2019-18650: An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSR An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
nvd
CVE-2011-3629P4HIGHCVSS 7.5fixed in 1.7.22020-02-04
CVE-2011-3629 [HIGH] CWE-326 CVE-2011-3629: Joomla! core 1.7.1 allows information disclosure due to weak encryption Joomla! core 1.7.1 allows information disclosure due to weak encryption
nvd
CVE-2024-21722P4MEDIUMCVSS 6.3≥ 3.2.0, < 3.10.15≥ 4.0.0, < 4.4.3+1 more2024-02-29
CVE-2024-21722 [MEDIUM] CWE-613 CVE-2024-21722: The MFA management features did not properly terminate existing user sessions when a user's MFA meth The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
nvd
CVE-2018-11321P4MEDIUMCVSS 6.5fixed in 3.8.82018-05-22
CVE-2018-11321 [MEDIUM] CWE-20 CVE-2018-11321: An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows user An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
nvd
CVE-2026-92224P4MEDIUMCVSS 6.7≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-92224 [MEDIUM] CWE-79 CVE-2026-92224: Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - T Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.
nvd
CVE-2026-92226P3MEDIUMCVSS 6.0≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-92226 [MEDIUM] CWE-284 CVE-2026-92226: Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4. Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.
nvd
CVE-2026-90913P3MEDIUMCVSS 5.5≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90913 [MEDIUM] CWE-284 CVE-2026-90913: Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joom Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints.
nvd
Joomla ! vulnerabilities | cvebase