Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Joomla! CMS — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in Joomla! CMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities associated with the Joomla! CMS product. It collects known security defects disclosed by the vendor or discovered through community reporting, covering incidents from the product's initial release through the most recent advisory. Readers can use this resource to track the vendor’s security advisories, analyze the specific class of weaknesses impacting this content management system, and review the full historical record of vulnerabilities affecting Joomla! installations. The data spans the complete lifecycle of the product, providing a chronological view of security issues without listing individual CVE identifiers.

Vendor: Joomla! Project

CVE ID Title CVSS Severity Published
CVE-2026-90915 Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-22 7.0 High 2026-09-29
CVE-2026-92226 Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-284 7.0 High 2026-09-29
CVE-2026-92224 Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-79 5.9 Medium 2026-09-29
CVE-2026-90907 Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 CWE-639 6.9 Medium 2026-09-29
CVE-2026-90914 Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-79 5.9 Medium 2026-09-29
CVE-2026-92231 Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 CWE-79 7.1 High 2026-09-29
CVE-2026-90918 Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-79 6.9 Medium 2026-09-29
CVE-2026-92222 Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-918 8.9 High 2026-09-29
CVE-2026-92223 Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 CWE-284 5.1 Medium 2026-09-29
CVE-2026-90917 Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-284 6.9 Medium 2026-09-29
CVE-2026-92225 Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-79 5.9 Medium 2026-09-29
CVE-2026-92227 Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-287 8.2 High 2026-09-29
CVE-2026-92232 Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 CWE-79 7.1 High 2026-09-29
CVE-2026-90916 Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-284 5.1 Medium 2026-09-29
CVE-2026-90913 Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 CWE-284 7.0 High 2026-09-29
CVE-2026-90906 Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 CWE-79 5.9 Medium 2026-09-29
CVE-2026-71573 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 CWE-93 6.9 Medium 2026-08-18
CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 CWE-284 5.1 Medium 2026-08-18
CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 CWE-79 5.1 Medium 2026-08-18
CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 CWE-284 5.1 Medium 2026-08-18
CVE-2026-71572 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 CWE-93 4.8 Medium 2026-08-18
CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 CWE-287 8.2 High 2026-08-18
CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 CWE-284 5.1 Medium 2026-08-18
CVE-2026-72532 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 CWE-284 5.1 Medium 2026-08-18
CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 CWE-434 8.9 High 2026-08-18
CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 CWE-284 8.5 High 2026-08-18
CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer CWE-79 - - 2026-07-07
CVE-2026-48947 Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints CWE-284 - - 2026-07-07
CVE-2026-48958 Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints CWE-284 - - 2026-07-07
CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates CWE-79 - - 2026-07-07

All 137 known CVE vulnerabilities affecting Joomla! CMS with full Chinese analysis, references, and POCs where available.