← Back

Joomla

joomla

Vendor: Joomla • 405 CVEs

CVEs (405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomla
1Joomla
Nov 21, 2024
May 22, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroye...Show more
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.Show less
1Joomla
1Joomla
Nov 21, 2024
May 22, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.
1Joomla
1Joomla
Nov 21, 2024
May 22, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
1Joomla
1Joomla
Nov 21, 2024
May 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
1Joomla
1Joomla
Jun 17, 2026
Mar 15, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
1Joomla
1Joomla
Jun 17, 2026
Jan 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
1Joomla
1Joomla
May 13, 2026
Nov 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
1Joomla
1Joomla
May 13, 2026
Nov 10, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
1Joomla
1Joomla
May 13, 2026
Sep 20, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
1Joomla
1Joomla
May 13, 2026
Sep 20, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
1Joomla
1Joomla
May 13, 2026
Sep 20, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
1Joomla
1Joomla
May 13, 2026
Aug 2, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
1Joomla
1Joomla
May 13, 2026
Jul 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
1Joomla
1Joomla
May 13, 2026
Jul 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
1Joomla
1Joomla
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
1Joomla
1Joomla
May 13, 2026
May 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.