← Back

Joomla

joomla

Vendor: Joomla • 405 CVEs

CVEs (405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms.
1Joomla
1Joomla
Jun 17, 2026
Aug 26, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
1Joomla
1Joomla
Jun 17, 2026
Aug 26, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Jun 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
1Joomla
1Joomla
Jun 17, 2026
Jun 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
1Joomla
1Joomla
Jun 17, 2026
Jun 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
1Joomla
1Joomla
Jun 17, 2026
Jun 2, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
1Joomla
1Joomla
Jun 17, 2026
Apr 21, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
1Joomla
1Joomla
Jun 17, 2026
Apr 21, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
1Joomla
1Joomla
Jun 17, 2026
Apr 21, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
1Joomla
1Joomla
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.