Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Joomla! Project — Vulnerabilities & Security Advisories 124

Browse all 124 CVE security advisories affecting Joomla! Project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Joomla! Project develops an open-source content management system widely used for building websites and online applications. Historically, its codebase has been associated with numerous security flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from insufficient input validation and improper access controls within extensions or core components. With eighty-two recorded CVEs, the project demonstrates a pattern of recurring weaknesses that require diligent patching. While the core framework itself has seen improvements, the extensive ecosystem of third-party extensions frequently introduces additional attack surfaces. Major incidents have highlighted the critical importance of timely updates and secure configuration practices. Administrators must prioritize vulnerability management to mitigate risks, as the platform’s popularity makes it a frequent target for automated exploitation attempts seeking to compromise underlying server infrastructure.

Found 121 results / 124 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-71573 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-93 6.9 Medium 2026-08-18
CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-284 5.1 Medium 2026-08-18
CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-79 5.1 Medium 2026-08-18
CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 — Joomla! CMS CWE-284 5.1 Medium 2026-08-18
CVE-2026-71572 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-93 4.8 Medium 2026-08-18
CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 — Joomla! CMS CWE-287 8.2 High 2026-08-18
CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-284 5.1 Medium 2026-08-18
CVE-2026-72532 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-284 5.1 Medium 2026-08-18
CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-434 8.9 High 2026-08-18
CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 — Joomla! CMS CWE-284 8.5 High 2026-08-18
CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer — Joomla! CMS CWE-79 - - 2026-07-07
CVE-2026-48947 Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints — Joomla! CMS CWE-284 - - 2026-07-07
CVE-2026-48958 Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints — Joomla! CMS CWE-284 - - 2026-07-07
CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates — Joomla! CMS CWE-79 - - 2026-07-07
CVE-2026-48955 Joomla! Core - [20260709] - Incorrect Access Control in com_workflow — Joomla! CMS CWE-284 - - 2026-07-07
CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules — Joomla! CMS CWE-284 - - 2026-07-07
CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints — Joomla! CMS CWE-284 - - 2026-07-07
CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts — Joomla! CMS CWE-79 - - 2026-07-07
CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout — Joomla! CMS CWE-79 - - 2026-07-07
CVE-2026-48948 Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download — Joomla! CMS CWE-284 - - 2026-07-07
CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management — Joomla! CMS CWE-79 - - 2026-07-07
CVE-2026-48954 Joomla! Core - [20260708] - XSS through language overrides — Joomla! CMS CWE-79 - - 2026-07-07
CVE-2026-35221 Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder — Joomla! CMS CWE-89 - - 2026-05-26
CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass — Joomla! CMS CWE-287 - - 2026-05-26
CVE-2026-35220 Joomla! Core - [20260505] - CSRF in user activation endpoint — Joomla! CMS CWE-352 - - 2026-05-26
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter — Joomla! CMS CWE-22 - - 2026-05-26
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags — Joomla! CMS CWE-89 - - 2026-05-26
CVE-2026-40384 Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint — Joomla! CMS CWE-22 - - 2026-05-26
CVE-2026-48897 Joomla! Core - [20260512] - MFA Authentication Bypass — Joomla! CMS CWE-287 - - 2026-05-26
CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations — Joomla! CMS CWE-79 - - 2026-05-26

This page lists every published CVE security advisory associated with Joomla! Project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.