Home / CVEs we hold for Joomla! CVEs we hold for Joomla! Records whose assigning authority named Joomla! as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 Joomla! Framework Filesystem package CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and… Joomla! CMS CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 Joomla! CMS CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 Joomla! CMS CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 Joomla! CMS CVE-2026-72532 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 Joomla! CMS CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7… Joomla! CMS CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 Joomla! CMS CVE-2026-71573 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 Joomla! CMS CVE-2026-71572 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 Joomla! CMS CVE-2026-48958 Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints Joomla! CMS CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints Joomla! CMS CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules Joomla! CMS CVE-2026-48955 Joomla! Core - [20260709] - Incorrect Access Control in com_workflow Joomla! CMS CVE-2026-48954 Joomla! Core - [20260708] - XSS through language overrides Joomla! CMS CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout Joomla! CMS CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer Joomla! CMS CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts Joomla! CMS CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates Joomla! CMS CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management Joomla! CMS CVE-2026-48948 Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download Joomla! CMS CVE-2026-48947 Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints Joomla! CMS CVE-2026-48905 Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code. Joomla! Framework Filter package CVE-2026-48904 Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints Joomla! CMS CVE-2026-48903 Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code. Joomla! Framework Filter package CVE-2026-48902 Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links Joomla! CMS CVE-2026-48901 Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects Joomla! CMS CVE-2026-48900 Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler Joomla! CMS CVE-2026-48899 Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins Joomla! CMS CVE-2026-48898 Joomla! Core - [20260513] - Privilege escalation through com_users batch task Joomla! CMS CVE-2026-48897 Joomla! Core - [20260512] - MFA Authentication Bypass Joomla! CMS CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass Joomla! CMS CVE-2026-40384 Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint Joomla! CMS CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter Joomla! CMS CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints Joomla! CMS CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags Joomla! CMS CVE-2026-35221 Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder Joomla! CMS CVE-2026-35220 Joomla! Core - [20260505] - CSRF in user activation endpoint Joomla! CMS CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links Joomla! CMS CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory Joomla! CMS CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations Joomla! CMS CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules Joomla! CMS CVE-2026-23899 Joomla! Core - [20260306] - Improper access check in webservice endpoints Joomla! CMS CVE-2026-23898 Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate Joomla! CMS CVE-2026-21632 Joomla! Core - [20260304] - XSS vectors in various article title outputs Joomla! CMS CVE-2026-21631 Joomla! Core - [20260303] - XSS vector in com_associations comparison view Joomla! CMS CVE-2026-21630 Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint Joomla! CMS CVE-2026-21629 Joomla! Core - [20260301] - ACL hardening in com_ajax Joomla! CMS CVE-2025-63083 Joomla! Core - [20260102] - XSS vector in the pagebreak plugin Joomla! CMS CVE-2025-63082 Joomla! Core - [20260101] - Inadequate content filtering for data URLs Joomla! CMS CVE-2025-54477 Joomla! Core - [20250902] User-Enumeration in passkey authentication method Joomla! CMS CVE-2025-54476 Joomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter code Joomla! CMS CVE-2025-25227 [20250402] - Joomla Core - MFA Authentication Bypass Joomla! CMS CVE-2025-25226 [20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database package Joomla! Framework CVE-2025-22213 [20250301] - Core - Malicious file uploads via Media Manager Joomla! CMS CVE-2025-22207 [20250201] - Core - SQL injection vulnerability in Scheduled Tasks component Joomla! CMS CVE-2024-40749 [20250103] - Core - Read ACL violation in multiple core views Joomla! CMS CVE-2024-40748 [20250102] - Core - XSS vector in the id attribute of menu lists Joomla! CMS CVE-2024-40747 [20250101] - Core - XSS vectors in module chromes Joomla! CMS CVE-2024-40743 [20240805] - Core - XSS vectors in Outputfilter::strip* methods Joomla! CMS CVE-2024-27187 [20240804] - Core - Improper ACL for backend profile view Joomla! CMS CVE-2024-27186 [20240803] - Core - XSS in HTML Mail Templates Joomla! CMS CVE-2024-27185 [20240802] - Core - Cache Poisoning in Pagination Joomla! CMS CVE-2024-27184 [20240801] - Core - Inadequate validation of internal URLs Joomla! CMS CVE-2024-26279 [20240704] - Core - XSS in Wrapper extensions Joomla! CMS CVE-2024-26278 [20240705] - Core - XSS in com_fields default field value Joomla! CMS CVE-2024-21731 [20240703] - Core - XSS in StringHelper::truncate method Joomla! CMS CVE-2024-21730 [20240702] - Core - Self-XSS in fancyselect list field layout Joomla! CMS CVE-2024-21729 [20240701] - Core - XSS in accessible media selection field Joomla! CMS CVE-2024-21726 [20240205] - Core - Inadequate content filtering within the filter code Joomla! CMS CVE-2024-21725 [20240204] - Core - XSS in mail address outputs Joomla! CMS CVE-2024-21724 [20240203] - Core - XSS in media selection fields Joomla! CMS CVE-2024-21723 [20240202] - Core - Open redirect in installation application Joomla! CMS CVE-2024-21722 [20240201] - Core - Insufficient session expiration in MFA management views Joomla! CMS CVE-2023-40626 [20231101] - Core - Exposure of environment variables Joomla! CMS CVE-2023-23755 [20230502] - Core - Bruteforce prevention within the mfa screen Joomla! CMS CVE-2023-23754 [20230501] - Core - Open Redirect and XSS within the mfa select Joomla! CMS CVE-2023-23752 [20230201] - Core - Improper access check in webservice endpoints Joomla! CMS CVE-2023-23751 [20230102] - Core - Missing ACL checks for com_actionlogs Joomla! CMS CVE-2023-23750 [20230101] - Core - CSRF within post-installation messages Joomla! CMS CVE-2022-27914 [20221101] - Core - RXSS through reflection of user input in com_media Joomla! CMS CVE-2022-27913 [20221002] - Core - RXSS through reflection of user input in headings Joomla! CMS CVE-2022-27912 [20221001] - Core - Debug Mode leaks full request payloads including passwords Joomla! CMS CVE-2022-27911 [20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check' Joomla! CMS CVE-2022-23801 [20220309] - Core - XSS attack vector through SVG Joomla! CMS CVE-2022-23800 [20220308] - Core - Inadequate content filtering within the filter code Joomla! Project joomla/filter CVE-2022-23799 [20220307] - Core - Variable Tampering on JInput $_REQUEST data Joomla! Project joomla/input CVE-2022-23798 [20220306] - Core - Inadequate validation of internal URLs Joomla! CMS CVE-2022-23797 [20220305] - Core - Inadequate filtering on the selected Ids Joomla! CMS CVE-2022-23796 [20220304] - Core - Missing input validation within com_fields class inputs Joomla! CMS CVE-2022-23795 [20220303] - Core - User row are not bound to a authentication mechanism Joomla! CMS CVE-2022-23794 [20220302] - Core - Path Disclosure within filesystem error messages Joomla! Project joomla/filesystem CVE-2022-23793 [20220301] - Core - Zip Slip within the Tar extractor Joomla! Project joomla/archive CVE-2021-26040 [20210801] - Core - Insufficient access control for com_media deletion endpoint Joomla! CMS CVE-2021-26039 [20210705] - Core - XSS in com_media imagelist Joomla! CMS CVE-2021-26038 [20210704] - Core - Privilege escalation through com_installer Joomla! CMS CVE-2021-26037 [20210703] - Core - Lack of enforced session termination Joomla! CMS CVE-2021-26036 [20210702] - Core - DoS through usergroup table manipulation Joomla! CMS CVE-2021-26034 [20210503] - Core - CSRF in data download endpoints Joomla! CMS CVE-2021-26033 [20210502] - Core - CSRF in AJAX reordering endpoint Joomla! CMS CVE-2021-26032 [20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUpload Joomla! CMS CVE-2021-26031 [20210402] - Core - Inadequate filters on module layout settings Joomla! CMS CVE-2021-26030 [20210401] - Core - Escape xss in logo parameter error pages Joomla! CMS CVE-2021-26029 [20210309] - Core - Inadequate filtering of form contents could allow to overwrite the author field Joomla! CMS CVE-2021-26028 [20210308] - Core - Path Traversal within joomla/archive zip class Joomla! CMS CVE-2021-26027 [20210307] - Core - ACL violation within com_content frontend editing Joomla! CMS CVE-2021-23132 [20210306] - Core - com_media allowed paths that are not intended for image uploads Joomla! CMS CVE-2021-23131 [20210305] - Core - Input validation within the template manager Joomla! CMS CVE-2021-23130 [20210304] - Core - XSS within the feed parser library Joomla! CMS CVE-2021-23129 [20210303] - Core - XSS within alert messages showed to users Joomla! CMS CVE-2021-23128 [20210302] - Core - Potential Insecure FOFEncryptRandval Joomla! CMS CVE-2021-23127 [20210301] - Core - Insecure randomness within 2FA secret generation Joomla! CMS CVE-2021-23126 [20210301] - Core - Insecure randomness within 2FA secret generation Joomla! CMS CVE-2021-23125 [20210103] - Core - XSS in com_tags image parameters Joomla! CMS CVE-2021-23124 [20210102] - Core - XSS in mod_breadcrumbs aria-label attribute Joomla! CMS CVE-2021-23123 [20210101] - Core - com_modules exposes module names Joomla! CMS CVE-2020-35616 [20201107] - Core - Write ACL violation in multiple core views Joomla! CMS CVE-2020-35615 [20201106] - Core - CSRF in com_privacy emailexport feature Joomla! CMS CVE-2020-35614 [20201105] - Core - User Enumeration in backend login Joomla! CMS CVE-2020-35613 [20201104] - Core - SQL injection in com_users list view Joomla! CMS CVE-2020-35612 [20201103] - Core - Path traversal in mod_random_image Joomla! CMS CVE-2020-35611 [20201102] - Core - Disclosure of secrets in Global Configuration page Joomla! CMS CVE-2020-35610 [20201101] - Core - com_finder ignores access levels on autosuggest Joomla! CMS CVE-2011-4906 no title held Joomla! Tiny browser included with TinyMCE 3.0 134 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.