Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2026-35222

Published May 26, 2026

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35221

Published May 26, 2026

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35220

Published May 26, 2026

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30895

Published May 26, 2026

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30894

Published May 26, 2026

Lack of output escaping leads to a XSS vector in the content history component.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25901

Published May 26, 2026

Lack of output escaping leads to a XSS vector in the multilingual associations component.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25900

Published May 26, 2026

Lack of output escaping leads to a XSS vector in the feed modules.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23899

Published Apr 1, 2026

An improper access check allows unauthorized access to webservice endpoints.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23898

Published Apr 1, 2026

Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21632

Published Apr 1, 2026

Lack of output escaping for article titles leads to XSS vectors in various locations.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21631

Published Apr 1, 2026

Lack of output escaping leads to a XSS vector in the multilingual associations component.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-21630

Published Apr 1, 2026

Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21629

Published Apr 1, 2026

The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-63083

Published Jan 6, 2026

Lack of output escaping leads to a XSS vector in the pagebreak plugin.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63082

Published Jan 6, 2026

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25227

Published Apr 8, 2025

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25226

Published Apr 8, 2025

Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method.…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-40747

Published Jan 7, 2025

Various module chromes didn't properly process inputs, leading to XSS vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40743

Published Aug 20, 2024

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27187

Published Aug 20, 2024

Improper Access Controls allows backend users to overwrite their username when disallowed.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27186

Published Aug 20, 2024

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27185

Published Aug 20, 2024

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27184

Published Aug 20, 2024

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 974 CVEsPage 2 of 39