vciy

CVEs we hold for Joomla!

Records whose assigning authority named Joomla! as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-73373Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2Joomla! Framework Filesystem package
CVE-2026-73372Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and…Joomla! CMS
CVE-2026-73371Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2Joomla! CMS
CVE-2026-73337Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2Joomla! CMS
CVE-2026-73336Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2Joomla! CMS
CVE-2026-72532Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2Joomla! CMS
CVE-2026-72531Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7…Joomla! CMS
CVE-2026-71574Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2Joomla! CMS
CVE-2026-71573Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2Joomla! CMS
CVE-2026-71572Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2Joomla! CMS
CVE-2026-48958Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpointsJoomla! CMS
CVE-2026-48957Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpointsJoomla! CMS
CVE-2026-48956Joomla! Core - [20260710] - Incorrect Access Control in com_modulesJoomla! CMS
CVE-2026-48955Joomla! Core - [20260709] - Incorrect Access Control in com_workflowJoomla! CMS
CVE-2026-48954Joomla! Core - [20260708] - XSS through language overridesJoomla! CMS
CVE-2026-48953Joomla! Core - [20260707] - XSS in the generic image output layoutJoomla! CMS
CVE-2026-48952Joomla! Core - [20260706] - XSS in com_installerJoomla! CMS
CVE-2026-48951Joomla! Core - [20260705] - XSS in various modalreturn layoutsJoomla! CMS
CVE-2026-48950Joomla! Core - [20260704] - XSS in com_templatesJoomla! CMS
CVE-2026-48949Joomla! Core - [20260703] - XSS in MFA method managementJoomla! CMS
CVE-2026-48948Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf downloadJoomla! CMS
CVE-2026-48947Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpointsJoomla! CMS
CVE-2026-48905Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.Joomla! Framework Filter package
CVE-2026-48904Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpointsJoomla! CMS
CVE-2026-48903Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.Joomla! Framework Filter package
CVE-2026-48902Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset linksJoomla! CMS
CVE-2026-48901Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objectsJoomla! CMS
CVE-2026-48900Joomla! Core - [20260516] - Incorrect Access Control in com_schedulerJoomla! CMS
CVE-2026-48899Joomla! Core - [20260515] - Incorrect Access Control in sample data pluginsJoomla! CMS
CVE-2026-48898Joomla! Core - [20260513] - Privilege escalation through com_users batch taskJoomla! CMS
CVE-2026-48897Joomla! Core - [20260512] - MFA Authentication BypassJoomla! CMS
CVE-2026-48896Joomla! Core - [20260511] - MFA Authentication BypassJoomla! CMS
CVE-2026-40384Joomla! Core - [20260510] - Path traversal in com_media webservice endpointJoomla! CMS
CVE-2026-40383Joomla! Core - [20260509] - LFI in HTMLView layout parameterJoomla! CMS
CVE-2026-35223Joomla! Core - [20260508] - Improper access check in com_config webservice endpointsJoomla! CMS
CVE-2026-35222Joomla! Core - [20260507] - Authenticated blind SQLi in com_tagsJoomla! CMS
CVE-2026-35221Joomla! Core - [20260506] - Authenticated blind SQLi in com_finderJoomla! CMS
CVE-2026-35220Joomla! Core - [20260505] - CSRF in user activation endpointJoomla! CMS
CVE-2026-30895Joomla! Core - [20260504] - XSS in readmore linksJoomla! CMS
CVE-2026-30894Joomla! Core - [20260503] - XSS in com_contenthistoryJoomla! CMS
CVE-2026-25901Joomla! Core - [20260502] - XSS in com_associationsJoomla! CMS
CVE-2026-25900Joomla! Core - [20260501] - XSS in feed modulesJoomla! CMS
CVE-2026-23899Joomla! Core - [20260306] - Improper access check in webservice endpointsJoomla! CMS
CVE-2026-23898Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdateJoomla! CMS
CVE-2026-21632Joomla! Core - [20260304] - XSS vectors in various article title outputsJoomla! CMS
CVE-2026-21631Joomla! Core - [20260303] - XSS vector in com_associations comparison viewJoomla! CMS
CVE-2026-21630Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpointJoomla! CMS
CVE-2026-21629Joomla! Core - [20260301] - ACL hardening in com_ajaxJoomla! CMS
CVE-2025-63083Joomla! Core - [20260102] - XSS vector in the pagebreak pluginJoomla! CMS
CVE-2025-63082Joomla! Core - [20260101] - Inadequate content filtering for data URLsJoomla! CMS
CVE-2025-54477Joomla! Core - [20250902] User-Enumeration in passkey authentication methodJoomla! CMS
CVE-2025-54476Joomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter codeJoomla! CMS
CVE-2025-25227[20250402] - Joomla Core - MFA Authentication BypassJoomla! CMS
CVE-2025-25226[20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database packageJoomla! Framework
CVE-2025-22213[20250301] - Core - Malicious file uploads via Media ManagerJoomla! CMS
CVE-2025-22207[20250201] - Core - SQL injection vulnerability in Scheduled Tasks componentJoomla! CMS
CVE-2024-40749[20250103] - Core - Read ACL violation in multiple core viewsJoomla! CMS
CVE-2024-40748[20250102] - Core - XSS vector in the id attribute of menu listsJoomla! CMS
CVE-2024-40747[20250101] - Core - XSS vectors in module chromesJoomla! CMS
CVE-2024-40743[20240805] - Core - XSS vectors in Outputfilter::strip* methodsJoomla! CMS
CVE-2024-27187[20240804] - Core - Improper ACL for backend profile viewJoomla! CMS
CVE-2024-27186[20240803] - Core - XSS in HTML Mail TemplatesJoomla! CMS
CVE-2024-27185[20240802] - Core - Cache Poisoning in PaginationJoomla! CMS
CVE-2024-27184[20240801] - Core - Inadequate validation of internal URLsJoomla! CMS
CVE-2024-26279[20240704] - Core - XSS in Wrapper extensionsJoomla! CMS
CVE-2024-26278[20240705] - Core - XSS in com_fields default field valueJoomla! CMS
CVE-2024-21731[20240703] - Core - XSS in StringHelper::truncate methodJoomla! CMS
CVE-2024-21730[20240702] - Core - Self-XSS in fancyselect list field layoutJoomla! CMS
CVE-2024-21729[20240701] - Core - XSS in accessible media selection fieldJoomla! CMS
CVE-2024-21726[20240205] - Core - Inadequate content filtering within the filter codeJoomla! CMS
CVE-2024-21725[20240204] - Core - XSS in mail address outputsJoomla! CMS
CVE-2024-21724[20240203] - Core - XSS in media selection fieldsJoomla! CMS
CVE-2024-21723[20240202] - Core - Open redirect in installation applicationJoomla! CMS
CVE-2024-21722[20240201] - Core - Insufficient session expiration in MFA management viewsJoomla! CMS
CVE-2023-40626[20231101] - Core - Exposure of environment variablesJoomla! CMS
CVE-2023-23755[20230502] - Core - Bruteforce prevention within the mfa screenJoomla! CMS
CVE-2023-23754[20230501] - Core - Open Redirect and XSS within the mfa selectJoomla! CMS
CVE-2023-23752[20230201] - Core - Improper access check in webservice endpointsJoomla! CMS
CVE-2023-23751[20230102] - Core - Missing ACL checks for com_actionlogsJoomla! CMS
CVE-2023-23750[20230101] - Core - CSRF within post-installation messagesJoomla! CMS
CVE-2022-27914[20221101] - Core - RXSS through reflection of user input in com_mediaJoomla! CMS
CVE-2022-27913[20221002] - Core - RXSS through reflection of user input in headingsJoomla! CMS
CVE-2022-27912[20221001] - Core - Debug Mode leaks full request payloads including passwordsJoomla! CMS
CVE-2022-27911[20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check'Joomla! CMS
CVE-2022-23801[20220309] - Core - XSS attack vector through SVGJoomla! CMS
CVE-2022-23800[20220308] - Core - Inadequate content filtering within the filter codeJoomla! Project joomla/filter
CVE-2022-23799[20220307] - Core - Variable Tampering on JInput $_REQUEST dataJoomla! Project joomla/input
CVE-2022-23798[20220306] - Core - Inadequate validation of internal URLsJoomla! CMS
CVE-2022-23797[20220305] - Core - Inadequate filtering on the selected IdsJoomla! CMS
CVE-2022-23796[20220304] - Core - Missing input validation within com_fields class inputsJoomla! CMS
CVE-2022-23795[20220303] - Core - User row are not bound to a authentication mechanismJoomla! CMS
CVE-2022-23794[20220302] - Core - Path Disclosure within filesystem error messagesJoomla! Project joomla/filesystem
CVE-2022-23793[20220301] - Core - Zip Slip within the Tar extractorJoomla! Project joomla/archive
CVE-2021-26040[20210801] - Core - Insufficient access control for com_media deletion endpointJoomla! CMS
CVE-2021-26039[20210705] - Core - XSS in com_media imagelistJoomla! CMS
CVE-2021-26038[20210704] - Core - Privilege escalation through com_installerJoomla! CMS
CVE-2021-26037[20210703] - Core - Lack of enforced session terminationJoomla! CMS
CVE-2021-26036[20210702] - Core - DoS through usergroup table manipulationJoomla! CMS
CVE-2021-26035[20210701] - Core - XSS in JForm Rules fieldJoomla! CMS
CVE-2021-26034[20210503] - Core - CSRF in data download endpointsJoomla! CMS
CVE-2021-26033[20210502] - Core - CSRF in AJAX reordering endpointJoomla! CMS
CVE-2021-26032[20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUploadJoomla! CMS
CVE-2021-26031[20210402] - Core - Inadequate filters on module layout settingsJoomla! CMS
CVE-2021-26030[20210401] - Core - Escape xss in logo parameter error pagesJoomla! CMS
CVE-2021-26029[20210309] - Core - Inadequate filtering of form contents could allow to overwrite the author fieldJoomla! CMS
CVE-2021-26028[20210308] - Core - Path Traversal within joomla/archive zip classJoomla! CMS
CVE-2021-26027[20210307] - Core - ACL violation within com_content frontend editingJoomla! CMS
CVE-2021-23132[20210306] - Core - com_media allowed paths that are not intended for image uploadsJoomla! CMS
CVE-2021-23131[20210305] - Core - Input validation within the template managerJoomla! CMS
CVE-2021-23130[20210304] - Core - XSS within the feed parser libraryJoomla! CMS
CVE-2021-23129[20210303] - Core - XSS within alert messages showed to usersJoomla! CMS
CVE-2021-23128[20210302] - Core - Potential Insecure FOFEncryptRandvalJoomla! CMS
CVE-2021-23127[20210301] - Core - Insecure randomness within 2FA secret generationJoomla! CMS
CVE-2021-23126[20210301] - Core - Insecure randomness within 2FA secret generationJoomla! CMS
CVE-2021-23125[20210103] - Core - XSS in com_tags image parametersJoomla! CMS
CVE-2021-23124[20210102] - Core - XSS in mod_breadcrumbs aria-label attributeJoomla! CMS
CVE-2021-23123[20210101] - Core - com_modules exposes module namesJoomla! CMS
CVE-2020-35616[20201107] - Core - Write ACL violation in multiple core viewsJoomla! CMS
CVE-2020-35615[20201106] - Core - CSRF in com_privacy emailexport featureJoomla! CMS
CVE-2020-35614[20201105] - Core - User Enumeration in backend loginJoomla! CMS
CVE-2020-35613[20201104] - Core - SQL injection in com_users list viewJoomla! CMS
CVE-2020-35612[20201103] - Core - Path traversal in mod_random_imageJoomla! CMS
CVE-2020-35611[20201102] - Core - Disclosure of secrets in Global Configuration pageJoomla! CMS
CVE-2020-35610[20201101] - Core - com_finder ignores access levels on autosuggestJoomla! CMS
CVE-2012-1563no title heldJoomla!
CVE-2012-1562no title heldJoomla! core
CVE-2011-4937no title heldJoomla!
CVE-2011-4912no title heldJoomla!
CVE-2011-4908no title heldJoomla! TinyBrowser Plugin
CVE-2011-4907no title heldJoomla!
CVE-2011-4906no title heldJoomla! Tiny browser included with TinyMCE 3.0
CVE-2011-3629no title heldJoomla! core
CVE-2011-3595no title heldJoomla!
CVE-2011-1151no title heldJoomla!

134 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.