Joomla ! vulnerabilities
334 known vulnerabilities affecting joomla/joomla_!.
Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4
Vulnerabilities
Page 8 of 17
CVE-2019-12764P4MEDIUMCVSS 6.5≥ 3.8.13, < 3.9.72019-06-11
CVE-2019-12764 [MEDIUM] CVE-2019-12764: An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be ma
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
nvd
CVE-2026-73336P4MEDIUMCVSS 6.4≥ 5.1.0, < 5.4.8≥ 6.0.0, ≤ 6.1.32026-08-18
CVE-2026-73336 [MEDIUM] CWE-79 CVE-2026-73336: Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Impr
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
nvd
CVE-2006-4470P4HIGHCVSS 7.5fixed in 1.0.112006-08-31
CVE-2006-4470 [HIGH] CVE-2006-4470: Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to
Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.
nvd
CVE-2017-7989P4MEDIUMCVSS 6.5v3.2.0v3.2.1+26 more2017-04-25
CVE-2017-7989 [MEDIUM] CWE-434 CVE-2017-7989: In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege u
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
nvd
CVE-2012-1598P4HIGHCVSS 7.5v1.5.0v1.5.1+24 more2012-12-03
CVE-2012-1598 [HIGH] CWE-264 CVE-2012-1598: Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient rando
Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."
nvd
CVE-2026-72532P4MEDIUMCVSS 5.4≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-08-18
CVE-2026-72532 [MEDIUM] CWE-284 CVE-2026-72532: Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
nvd
CVE-2026-72531P4MEDIUMCVSS 5.4≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-08-18
CVE-2026-72531 [MEDIUM] CWE-284 CVE-2026-72531: Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
nvd
CVE-2026-90914P4MEDIUMCVSS 6.4≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90914 [MEDIUM] CWE-79 CVE-2026-90914: Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.
Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.
nvd
CVE-2026-90917P4MEDIUMCVSS 5.3≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90917 [MEDIUM] CWE-284 CVE-2026-90917: Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5
Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.
nvd
CVE-2026-90907P4MEDIUMCVSS 5.3≥ 1.5.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90907 [MEDIUM] CWE-639 CVE-2026-90907: Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in
Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.
nvd
CVE-2015-5397P4MEDIUMCVSS 6.8v3.2.0v3.2.1+13 more2015-07-14
CVE-2015-5397 [MEDIUM] CWE-352 CVE-2015-5397: Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.
Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.
nvd
CVE-2021-26033P4MEDIUMCVSS 6.5≥ 3.0.0, ≤ 3.9.262021-05-26
CVE-2021-26033 [MEDIUM] CWE-352 CVE-2021-26033: An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnera
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.
nvd
CVE-2018-11324P4MEDIUMCVSS 5.9fixed in 3.8.82018-05-22
CVE-2018-11324 [MEDIUM] CWE-362 CVE-2018-11324: An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as rem
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.
nvd
CVE-2026-48950P4MEDIUMCVSS 6.1≥ 4.0.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48950 [MEDIUM] CWE-79 CVE-2026-48950: Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
nvd
CVE-2026-48949P4MEDIUMCVSS 6.1≥ 4.2.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48949 [MEDIUM] CWE-79 CVE-2026-48949: Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of validation leads to an XSS vulnerability in the MFA management views.
nvd
CVE-2026-71572P4MEDIUMCVSS 5.4≥ 3.0.0, < 5.4.8≥ 6.0.0, ≤ 6.1.32026-08-18
CVE-2026-71572 [MEDIUM] CWE-93 CVE-2026-71572: Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
nvd
CVE-2026-90918P4MEDIUMCVSS 5.3≥ 4.0.0, < 5.4.8≥ 6.0.0, < 6.1.32026-09-29
CVE-2026-90918 [MEDIUM] CWE-79 CVE-2026-90918: Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - T
Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
nvd
CVE-2026-48956P4MEDIUMCVSS 5.0≥ 4.0.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48956 [MEDIUM] CWE-284 CVE-2026-48956: An improper access check allows users to display a list of modules in the frontend.
An improper access check allows users to display a list of modules in the frontend.
nvd
CVE-2026-48947P4MEDIUMCVSS 4.9≥ 4.1.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48947 [MEDIUM] CWE-284 CVE-2026-48947: An improper access check allows privileged users to overwrite media files without editing permission
An improper access check allows privileged users to overwrite media files without editing permissions.
nvd
CVE-2020-15696P4MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.9.192020-07-15
CVE-2020-15696 [MEDIUM] CWE-79 CVE-2020-15696: An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS a
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
nvd