Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Joomla! Project — Vulnerabilities & Security Advisories 114

Browse all 114 CVE security advisories affecting Joomla! Project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Joomla! Project develops an open-source content management system widely used for building websites and online applications. Historically, its codebase has been associated with numerous security flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from insufficient input validation and improper access controls within extensions or core components. With eighty-two recorded CVEs, the project demonstrates a pattern of recurring weaknesses that require diligent patching. While the core framework itself has seen improvements, the extensive ecosystem of third-party extensions frequently introduces additional attack surfaces. Major incidents have highlighted the critical importance of timely updates and secure configuration practices. Administrators must prioritize vulnerability management to mitigate risks, as the platform’s popularity makes it a frequent target for automated exploitation attempts seeking to compromise underlying server infrastructure.

Found 111 results / 114Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48947 Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48958 Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48955 Joomla! Core - [20260709] - Incorrect Access Control in com_workflow — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48948 Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download — Joomla! CMSCWE-284--2026-07-07
CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management — Joomla! CMSCWE-79--2026-07-07
CVE-2026-48954 Joomla! Core - [20260708] - XSS through language overrides — Joomla! CMSCWE-79--2026-07-07
CVE-2026-35221 Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder — Joomla! CMSCWE-89--2026-05-26
CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass — Joomla! CMSCWE-287--2026-05-26
CVE-2026-35220 Joomla! Core - [20260505] - CSRF in user activation endpoint — Joomla! CMSCWE-352--2026-05-26
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter — Joomla! CMSCWE-22--2026-05-26
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags — Joomla! CMSCWE-89--2026-05-26
CVE-2026-40384 Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint — Joomla! CMSCWE-22--2026-05-26
CVE-2026-48897 Joomla! Core - [20260512] - MFA Authentication Bypass — Joomla! CMSCWE-287--2026-05-26
CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations — Joomla! CMSCWE-79--2026-05-26
CVE-2026-48899 Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins — Joomla! CMSCWE-284--2026-05-26
CVE-2026-48900 Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler — Joomla! CMSCWE-284--2026-05-26
CVE-2026-48902 Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links — Joomla! CMS--2026-05-26
CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints — Joomla! CMSCWE-284--2026-05-26
CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules — Joomla! CMSCWE-79--2026-05-26
CVE-2026-48904 Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints — Joomla! CMSCWE-284--2026-05-26
CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links — Joomla! CMSCWE-79--2026-05-26
CVE-2026-48898 Joomla! Core - [20260513] - Privilege escalation through com_users batch task — Joomla! CMSCWE-284--2026-05-26
CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory — Joomla! CMSCWE-79--2026-05-26
CVE-2026-48901 Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects — Joomla! CMS--2026-05-26

This page lists every published CVE security advisory associated with Joomla! Project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.