Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Joomla! CMS — Vulnerabilities & Security Advisories 121

All 121 CVE vulnerabilities found in Joomla! CMS, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Joomla! CMS, focusing on the Common Weakness Enumeration (CWE) taxonomy and associated weakness tags. It compiles a comprehensive history of security flaws affecting this popular open-source content management system, spanning from its early releases through recent iterations. The data covers a wide spectrum of issue types, including SQL injection, cross-site scripting, and remote code execution vulnerabilities, providing a holistic view of the product's security landscape over time. Readers can use this resource to track vendor advisories and understand the evolution of specific weakness classes within the Joomla ecosystem. By exploring the detailed breakdown of vulnerabilities, users can look up a product's vulnerability history to identify recurring patterns or persistent security gaps. This aggregated view aids developers and security analysts in assessing risk, prioritizing patches, and implementing more robust defense mechanisms. The page does not serve as an official vendor statement but rather as a curated collection of publicly disclosed security issues. It aims to provide clarity on the magnitude and nature of past exploits, helping stakeholders make informed decisions about system integrity and maintenance schedules. Through structured categorization, the information allows for deeper analysis of how certain code structures may lead to specific failure modes. This approach supports proactive security posture improvements by highlighting areas that have historically been prone to attacks, thereby encouraging continuous monitoring and timely updates to mitigate potential threats effectively.

Vendor: Joomla! Project

CVE IDTitleCVSSSeverityPublished
CVE-2026-48899 Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins CWE-284--2026-05-26
CVE-2026-48900 Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler CWE-284--2026-05-26
CVE-2026-48902 Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links --2026-05-26
CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints CWE-284--2026-05-26
CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules CWE-79--2026-05-26
CVE-2026-48904 Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints CWE-284--2026-05-26
CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links CWE-79--2026-05-26
CVE-2026-48898 Joomla! Core - [20260513] - Privilege escalation through com_users batch task CWE-284--2026-05-26
CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory CWE-79--2026-05-26
CVE-2026-48901 Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects --2026-05-26
CVE-2026-21630 Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint CWE-89 9.8AICriticalAI2026-04-01
CVE-2026-23898 Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate CWE-73 8.6 High2026-04-01
CVE-2026-21629 Joomla! Core - [20260301] - ACL hardening in com_ajax CWE-284 9.8AICriticalAI2026-04-01
CVE-2026-23899 Joomla! Core - [20260306] - Improper access check in webservice endpoints CWE-284 8.1AIHighAI2026-04-01
CVE-2026-21631 Joomla! Core - [20260303] - XSS vector in com_associations comparison view CWE-79 6.1AIMediumAI2026-04-01
CVE-2026-21632 Joomla! Core - [20260304] - XSS vectors in various article title outputs CWE-79 5.4AIMediumAI2026-04-01
CVE-2025-63082 Joomla! Core - [20260101] - Inadequate content filtering for data URLs CWE-79 6.1 -2026-01-06
CVE-2025-63083 Joomla! Core - [20260102] - XSS vector in the pagebreak plugin CWE-79 6.1 -2026-01-06
CVE-2025-54477 Joomla! Core - [20250902] User-Enumeration in passkey authentication method CWE-203 5.3AIMediumAI2025-09-30
CVE-2025-54476 Joomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter code CWE-79 6.1AIMediumAI2025-09-30
CVE-2025-25227 [20250402] - Joomla Core - MFA Authentication Bypass CWE-287 8.1 -2025-04-08
CVE-2025-22213 [20250301] - Core - Malicious file uploads via Media Manager CWE-434 8.8 -2025-03-11
CVE-2025-22207 [20250201] - Core - SQL injection vulnerability in Scheduled Tasks component CWE-89 8.8 -2025-02-18
CVE-2024-40749 [20250103] - Core - Read ACL violation in multiple core views CWE-284 6.5 -2025-01-07
CVE-2024-40747 [20250101] - Core - XSS vectors in module chromes CWE-79 6.1 -2025-01-07
CVE-2024-40748 [20250102] - Core - XSS vector in the id attribute of menu lists CWE-79 8.2 -2025-01-07
CVE-2024-27185 [20240802] - Core - Cache Poisoning in Pagination 7.5AIHighAI2024-08-20
CVE-2024-27186 [20240803] - Core - XSS in HTML Mail Templates CWE-79 6.1AIMediumAI2024-08-20
CVE-2024-27184 [20240801] - Core - Inadequate validation of internal URLs CWE-601 5.4AIMediumAI2024-08-20
CVE-2024-40743 [20240805] - Core - XSS vectors in Outputfilter::strip* methods CWE-79 6.1AIMediumAI2024-08-20

All 121 known CVE vulnerabilities affecting Joomla! CMS with full Chinese analysis, references, and POCs where available.