cbcvebase.

Joomla ! vulnerabilities

334 known vulnerabilities affecting joomla/joomla_!.

Total CVEs
334
CISA KEV
2
actively exploited
Public exploits
23
Exploited in wild
9
Severity breakdown
CRITICAL39HIGH82MEDIUM209LOW4

Vulnerabilities

Page 9 of 17
CVE-2015-8563P4MEDIUMCVSS 6.8v3.2.0v3.2.1+14 more2015-12-16
CVE-2015-8563 [MEDIUM] CWE-352 CVE-2015-8563: Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 thro Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2017-9934P4MEDIUMCVSS 6.1v1.7.3v1.7.4+73 more2017-07-17
CVE-2017-9934 [MEDIUM] CWE-79 CVE-2017-9934: Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to a Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
nvd
CVE-2021-26034P4MEDIUMCVSS 6.5≥ 3.0.0, ≤ 3.9.262021-05-26
CVE-2021-26034 [MEDIUM] CWE-352 CVE-2021-26034: An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnera An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.
nvd
CVE-2020-15695P4MEDIUMCVSS 6.3≥ 3.9.0, ≤ 3.9.192020-07-15
CVE-2020-15695 [MEDIUM] CWE-352 CVE-2020-15695: An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request secti An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
nvd
CVE-2020-15700P4MEDIUMCVSS 6.3≥ 3.7.0, ≤ 3.9.192020-07-15
CVE-2020-15700 [MEDIUM] CWE-352 CVE-2020-15700: An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoin An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
nvd
CVE-2020-35615P4MEDIUMCVSS 6.3≥ 2.5.0, ≤ 3.9.222020-12-28
CVE-2020-35615 [MEDIUM] CWE-352 CVE-2020-35615: An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport fe An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
nvd
CVE-2020-11890P4MEDIUMCVSS 5.3≥ 2.5.0, < 3.9.172020-04-21
CVE-2020-11890 [MEDIUM] CWE-20 CVE-2020-11890: An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
nvd
CVE-2023-23750P4MEDIUMCVSS 6.3≥ 4.0.0, ≤ 4.2.62023-02-01
CVE-2023-23750 [MEDIUM] CWE-352 CVE-2023-23750: An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerab An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
nvd
CVE-2026-48954P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48954 [MEDIUM] CWE-79 CVE-2026-48954: Improper validation leads to a generic XSS vector in the language override feature. Improper validation leads to a generic XSS vector in the language override feature.
nvd
CVE-2026-48905P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.6≥ 6.0.0, < 6.1.02026-05-26
CVE-2026-48905 [MEDIUM] CWE-79 CVE-2026-48905: Lack of input filtering leads to an XSS vector in the HTML filter code. Lack of input filtering leads to an XSS vector in the HTML filter code.
nvd
CVE-2008-4122P4HIGHCVSS 7.5v1.5.82008-12-19
CVE-2008-4122 [HIGH] CWE-319 CVE-2008-4122: Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes i Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2006-4468P4MEDIUMCVSS 6.8fixed in 1.0.112006-08-31
CVE-2006-4468 [MEDIUM] CWE-20 CVE-2006-4468: Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow a Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll
nvd
CVE-2018-6380P4MEDIUMCVSS 6.1fixed in 3.8.42018-01-30
CVE-2018-6380 [MEDIUM] CWE-79 CVE-2018-6380: In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
nvd
CVE-2018-6379P4MEDIUMCVSS 6.1fixed in 3.8.42018-01-30
CVE-2018-6379 [MEDIUM] CWE-79 CVE-2018-6379: In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
nvd
CVE-2018-12711P4MEDIUMCVSS 6.1≥ 1.6.0, ≤ 3.8.82018-06-26
CVE-2018-12711 [MEDIUM] CWE-79 CVE-2018-12711: An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3. An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.
nvd
CVE-2021-26035P4MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.9.272021-07-07
CVE-2021-26035 [MEDIUM] CWE-79 CVE-2021-26035: An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of t An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.
nvd
CVE-2026-48952P4MEDIUMCVSS 6.1≥ 4.0.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48952 [MEDIUM] CWE-79 CVE-2026-48952: Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
nvd
CVE-2026-48951P4MEDIUMCVSS 6.1≥ 4.0.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48951 [MEDIUM] CWE-79 CVE-2026-48951: Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
nvd
CVE-2026-48953P4MEDIUMCVSS 6.1≥ 4.0.0, < 5.4.7≥ 6.0.0, < 6.1.22026-07-07
CVE-2026-48953 [MEDIUM] CWE-79 CVE-2026-48953: Lack of escaping leads to an XSS vulnerability in the generic image output layout. Lack of escaping leads to an XSS vulnerability in the generic image output layout.
nvd
CVE-2026-25900P4MEDIUMCVSS 6.1≥ 3.0.0, < 5.4.6≥ 6.0.0, < 6.1.12026-05-26
CVE-2026-25900 [MEDIUM] CWE-79 CVE-2026-25900: Lack of output escaping leads to a XSS vector in the feed modules. Lack of output escaping leads to a XSS vector in the feed modules.
nvd
Joomla ! vulnerabilities | cvebase