← Back

Joomla

joomla

Vendor: Joomla • 405 CVEs

CVEs (405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomla
1Joomla
Jun 17, 2026
Jul 9, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
1Joomla
1Joomla
Jun 17, 2026
Jul 9, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
1Joomla
1Joomla
Jun 17, 2026
Jul 9, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
1Joomla
1Joomla
Jun 17, 2026
Jul 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
1Joomla
1Joomla
Jun 17, 2026
Jul 9, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
1Joomla
1Joomla
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inadequate content filtering leads to XSS vulnerabilities in various components.
1Joomla
1Joomla
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
1Joomla
1Joomla
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
1Joomla
1Joomla
Jun 17, 2026
Feb 29, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Inadequate parsing of URLs could result into an open redirect.
1Joomla
1Joomla
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
1Joomla
1Joomla
Jun 17, 2026
Nov 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
1Joomla
1Joomla
Jun 17, 2026
May 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
1Joomla
1Joomla
Jun 17, 2026
May 30, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
1Joomla
1Joomla
Jun 17, 2026
Feb 16, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
1Joomla
1Joomla
Jun 17, 2026
Feb 1, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
1Joomla
1Joomla
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
1Joomla
1Joomla
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
1Joomla
1Joomla
Jun 17, 2026
Oct 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
1Joomla
1Joomla
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
1Joomla
1Joomla
Jun 17, 2026
Aug 31, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.