← Back

Joomla

joomla

Vendor: Joomla • 405 CVEs

CVEs (405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
5.1 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into sche...Show more
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.Show less
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
5.1 MEDIUM· v4
6.4 MEDIUM· v3
N/A· v2
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
6.9 MEDIUM· v4
8.3 HIGH· v3
N/A· v2
Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
4.8 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file...Show more
Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.Show less
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
8.9 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead...Show more
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.Show less
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
5.1 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
1Joomla
1Joomla
Sep 3, 2026
Aug 18, 2026
8.5 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endp...Show more
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.Show less
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
6.4 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
6.4 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
An improper access check allows unauthorized users to access com_privacy datasets.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
6.4 MEDIUM· v4
5.0 MEDIUM· v3
N/A· v2
An improper access check allows users to display a list of modules in the frontend.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
6.4 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An improper access check allows unauthorized users to access workflow stage and transition information.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper validation leads to a generic XSS vector in the language override feature.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
1Joomla
1Joomla
Jul 9, 2026
Jul 7, 2026
5.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Lack of validation leads to an XSS vulnerability in the MFA management views.