Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Joomla! CMS — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in Joomla! CMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities associated with the Joomla! CMS product. It collects known security defects disclosed by the vendor or discovered through community reporting, covering incidents from the product's initial release through the most recent advisory. Readers can use this resource to track the vendor’s security advisories, analyze the specific class of weaknesses impacting this content management system, and review the full historical record of vulnerabilities affecting Joomla! installations. The data spans the complete lifecycle of the product, providing a chronological view of security issues without listing individual CVE identifiers.

Vendor: Joomla! Project

CVE ID Title CVSS Severity Published
CVE-2026-48955 Joomla! Core - [20260709] - Incorrect Access Control in com_workflow CWE-284 - - 2026-07-07
CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules CWE-284 - - 2026-07-07
CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints CWE-284 - - 2026-07-07
CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts CWE-79 - - 2026-07-07
CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout CWE-79 - - 2026-07-07
CVE-2026-48948 Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download CWE-284 - - 2026-07-07
CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management CWE-79 - - 2026-07-07
CVE-2026-48954 Joomla! Core - [20260708] - XSS through language overrides CWE-79 - - 2026-07-07
CVE-2026-35221 Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder CWE-89 - - 2026-05-26
CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass CWE-287 - - 2026-05-26
CVE-2026-35220 Joomla! Core - [20260505] - CSRF in user activation endpoint CWE-352 - - 2026-05-26
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter CWE-22 - - 2026-05-26
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags CWE-89 - - 2026-05-26
CVE-2026-40384 Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint CWE-22 - - 2026-05-26
CVE-2026-48897 Joomla! Core - [20260512] - MFA Authentication Bypass CWE-287 - - 2026-05-26
CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations CWE-79 - - 2026-05-26
CVE-2026-48899 Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins CWE-284 - - 2026-05-26
CVE-2026-48900 Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler CWE-284 - - 2026-05-26
CVE-2026-48902 Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links - - 2026-05-26
CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints CWE-284 - - 2026-05-26
CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules CWE-79 - - 2026-05-26
CVE-2026-48904 Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints CWE-284 - - 2026-05-26
CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links CWE-79 - - 2026-05-26
CVE-2026-48898 Joomla! Core - [20260513] - Privilege escalation through com_users batch task CWE-284 - - 2026-05-26
CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory CWE-79 - - 2026-05-26
CVE-2026-48901 Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects - - 2026-05-26
CVE-2026-21630 Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint CWE-89 9.8AI Critical AI 2026-04-01
CVE-2026-23898 Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate CWE-73 8.6 High 2026-04-01
CVE-2026-21629 Joomla! Core - [20260301] - ACL hardening in com_ajax CWE-284 9.8AI Critical AI 2026-04-01
CVE-2026-23899 Joomla! Core - [20260306] - Improper access check in webservice endpoints CWE-284 8.1AI High AI 2026-04-01

All 137 known CVE vulnerabilities affecting Joomla! CMS with full Chinese analysis, references, and POCs where available.