joomla
28 known vulnerabilities affecting joomla products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40383 | Medium | 0.5% | 9.8 | An improper validation of user-supplied input leads to a local file inclusion vu… | |
| CVE-2026-40384 | Medium | 0.4% | 7.5 | An improper validation of the search parameter of the com_media files API endpoi… | |
| CVE-2017-20267 | Medium | 0.4% | 8.2 | Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability… | |
| CVE-2026-73373 | Medium | 0.4% | 9.8 | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-… | |
| CVE-2026-35223 | Medium | 0.3% | 9.8 | An improper access check allows unauthorized access to com_config webservice end… | |
| CVE-2026-35221 | Medium | 0.3% | 9.8 | Improperly built filter clauses lead to a SQL injection vulnerability in the sea… | |
| CVE-2026-35222 | Medium | 0.3% | 9.8 | Improperly validated order clauses lead to a SQL injection vulnerability in com_… | |
| CVE-2026-48896 | Medium | 0.3% | 7.5 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| CVE-2026-48904 | Medium | 0.3% | 9.8 | An improper access check allows privelege escalation through the com_users group… | |
| CVE-2026-48898 | Medium | 0.3% | 9.8 | An improper access check allows privilege escalation through the com_users batch… | |
| CVE-2026-73337 | Medium | 0.3% | 7.5 | Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and … | |
| CVE-2026-48902 | Medium | 0.3% | 9.8 | The password and username reset features created plain http links for https conn… | |
| CVE-2026-71573 | Medium | 0.2% | 8.3 | Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.… | |
| CVE-2026-48901 | Medium | 0.2% | 7.5 | The InputFilter::getInstance() method omitted a security sensitive parameter fro… | |
| CVE-2026-48899 | Medium | 0.2% | 9.8 | An improper access check allows privilege escalation through the com_users batch… | |
| CVE-2026-48897 | Medium | 0.2% | 7.5 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| CVE-2026-73371 | Low | 0.2% | 4.3 | Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla… | |
| CVE-2026-73372 | Low | 0.2% | 4.3 | Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contac… | |
| CVE-2026-71574 | Low | 0.2% | 6.5 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endp… | |
| CVE-2026-73336 | Low | 0.2% | 6.4 | Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7… | |
| CVE-2026-72531 | Low | 0.2% | 5.4 | Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice end… | |
| CVE-2026-72532 | Low | 0.2% | 5.4 | Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoint… | |
| CVE-2026-30894 | Low | 0.2% | 6.1 | Lack of output escaping leads to a XSS vector in the content history component. | |
| CVE-2026-25901 | Low | 0.2% | 6.1 | Lack of output escaping leads to a XSS vector in the multilingual associations c… | |
| CVE-2026-30895 | Low | 0.2% | 6.1 | Lack of output escaping leads to a XSS vector in the readmore links for com_cont… | |
| CVE-2026-71572 | Low | 0.2% | 5.4 | Joomla! Core - [20260801] - Response header injection in download views in Jooml… | |
| CVE-2026-48900 | Low | 0.2% | 4.3 | An improper access check allowed low privileged users to edit the task types of … | |
| CVE-2026-48903 | Low | 0.1% | 6.1 | Inadequate content filtering within the checkAttribute methods leads to XSS vuln… |