Joomla! CMS
Joomla! Project- Product type
- Other
- Catalog vulnerabilities
- 121
Severity across 100 analyzed records
en
Severity across 100 analyzed records
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, Joomla! CMS has 22 security vulnerabilities published in the last 90 days. Of these, 3 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Joomla! CMS and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-71573Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-72531Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-73336Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-73372Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-71572Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-73337Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityHigh |
CVE-2026-73371Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-72532Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityMedium |
CVE-2026-73373Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityHigh |
CVE-2026-71574Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2026 | SeverityHigh |
CVE-2026-48952Joomla! Core - [20260706] - XSS in com_installer | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48947Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48958Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48950Joomla! Core - [20260704] - XSS in com_templates | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48955Joomla! Core - [20260709] - Incorrect Access Control in com_workflow | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48956Joomla! Core - [20260710] - Incorrect Access Control in com_modules | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48957Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48951Joomla! Core - [20260705] - XSS in various modalreturn layouts | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48953Joomla! Core - [20260707] - XSS in the generic image output layout | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48948Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48949Joomla! Core - [20260703] - XSS in MFA method management | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-48954Joomla! Core - [20260708] - XSS through language overrides | Exploitation statusNot known exploited | FixNot confirmed | Published07/07/2026 | SeverityMedium |
CVE-2026-35221Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48896Joomla! Core - [20260511] - MFA Authentication Bypass | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-35220Joomla! Core - [20260505] - CSRF in user activation endpoint | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-40383Joomla! Core - [20260509] - LFI in HTMLView layout parameter | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-35222Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-40384Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48897Joomla! Core - [20260512] - MFA Authentication Bypass | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-25901Joomla! Core - [20260502] - XSS in com_associations | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48899Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48900Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48902Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityCritical |
CVE-2026-35223Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-25900Joomla! Core - [20260501] - XSS in feed modules | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48904Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-30895Joomla! Core - [20260504] - XSS in readmore links | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48898Joomla! Core - [20260513] - Privilege escalation through com_users batch task | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-30894Joomla! Core - [20260503] - XSS in com_contenthistory | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityMedium |
CVE-2026-48901Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects | Exploitation statusNot known exploited | FixNot confirmed | Published05/26/2026 | SeverityHigh |
CVE-2026-21630Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint | Exploitation statusNot known exploited | FixNot confirmed | Published04/01/2026 | SeverityMedium |
CVE-2026-23898Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate | Exploitation statusNot known exploited | FixNot confirmed | Published04/01/2026 | SeverityHigh |
CVE-2026-21629Joomla! Core - [20260301] - ACL hardening in com_ajax | Exploitation statusNot known exploited | FixNot confirmed | Published04/01/2026 | SeverityMedium |
CVE-2026-23899Joomla! Core - [20260306] - Improper access check in webservice endpoints | Exploitation statusNot known exploited | FixNot confirmed | Published04/01/2026 | SeverityHigh |
CVE-2026-21631Joomla! Core - [20260303] - XSS vector in com_associations comparison view | Exploitation statusNot known exploited | FixNot confirmed | Published04/01/2026 | SeverityMedium |
CVE-2026-21632Joomla! Core - [20260304] - XSS vectors in various article title outputs | Exploitation statusNot known exploited | FixNot confirmed | Published04/01/2026 | SeverityMedium |
CVE-2025-63082Joomla! Core - [20260101] - Inadequate content filtering for data URLs | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2026 | SeverityMedium |
CVE-2025-63083Joomla! Core - [20260102] - XSS vector in the pagebreak plugin | Exploitation statusNot known exploited | FixNot confirmed | Published01/06/2026 | SeverityMedium |
CVE-2025-54477Joomla! Core - [20250902] User-Enumeration in passkey authentication method | Exploitation statusNot known exploited | FixNot confirmed | Published09/30/2025 | SeverityMedium |
CVE-2025-54476Joomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter code | Exploitation statusNot known exploited | FixNot confirmed | Published09/30/2025 | SeverityMedium |
CVE-2025-25227[20250402] - Joomla Core - MFA Authentication Bypass | Exploitation statusNot known exploited | FixNot confirmed | Published04/08/2025 | SeverityHigh |
CVE-2025-22213[20250301] - Core - Malicious file uploads via Media Manager | Exploitation statusNot known exploited | FixNot confirmed | Published03/11/2025 | SeverityHigh |
CVE-2025-22207[20250201] - Core - SQL injection vulnerability in Scheduled Tasks component | Exploitation statusNot known exploited | FixNot confirmed | Published02/18/2025 | SeverityMedium |
CVE-2024-40749[20250103] - Core - Read ACL violation in multiple core views | Exploitation statusNot known exploited | FixNot confirmed | Published01/07/2025 | SeverityHigh |
CVE-2024-40747[20250101] - Core - XSS vectors in module chromes | Exploitation statusNot known exploited | FixNot confirmed | Published01/07/2025 | SeverityMedium |
CVE-2024-40748[20250102] - Core - XSS vector in the id attribute of menu lists | Exploitation statusNot known exploited | FixNot confirmed | Published01/07/2025 | SeverityHigh |
CVE-2024-27185[20240802] - Core - Cache Poisoning in Pagination | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2024 | SeverityCritical |
CVE-2024-27186[20240803] - Core - XSS in HTML Mail Templates | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2024 | SeverityMedium |
CVE-2024-27184[20240801] - Core - Inadequate validation of internal URLs | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2024 | SeverityMedium |
CVE-2024-40743[20240805] - Core - XSS vectors in Outputfilter::strip* methods | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2024 | SeverityMedium |
CVE-2024-27187[20240804] - Core - Improper ACL for backend profile view | Exploitation statusNot known exploited | FixNot confirmed | Published08/20/2024 | SeverityHigh |
CVE-2024-21729[20240701] - Core - XSS in accessible media selection field | Exploitation statusNot known exploited | FixNot confirmed | Published07/09/2024 | SeverityMedium |
CVE-2024-21730[20240702] - Core - Self-XSS in fancyselect list field layout | Exploitation statusNot known exploited | FixNot confirmed | Published07/09/2024 | SeverityMedium |
CVE-2024-26279[20240704] - Core - XSS in Wrapper extensions | Exploitation statusNot known exploited | FixNot confirmed | Published07/09/2024 | SeverityMedium |
CVE-2024-26278[20240705] - Core - XSS in com_fields default field value | Exploitation statusNot known exploited | FixNot confirmed | Published07/09/2024 | SeverityMedium |
CVE-2024-21731[20240703] - Core - XSS in StringHelper::truncate method | Exploitation statusNot known exploited | FixNot confirmed | Published07/09/2024 | SeverityMedium |
CVE-2024-21723[20240202] - Core - Open redirect in installation application | Exploitation statusNot known exploited | FixNot confirmed | Published02/20/2024 | SeverityMedium |
CVE-2024-21725[20240204] - Core - XSS in mail address outputs | Exploitation statusNot known exploited | FixNot confirmed | Published02/20/2024 | SeverityMedium |
CVE-2024-21724[20240203] - Core - XSS in media selection fields | Exploitation statusNot known exploited | FixNot confirmed | Published02/20/2024 | SeverityMedium |
CVE-2024-21722[20240201] - Core - Insufficient session expiration in MFA management views | Exploitation statusNot known exploited | FixNot confirmed | Published02/20/2024 | SeverityMedium |
CVE-2024-21726[20240205] - Core - Inadequate content filtering within the filter code | Exploitation statusNot known exploited | FixNot confirmed | Published02/20/2024 | SeverityMedium |
CVE-2023-40626[20231101] - Core - Exposure of environment variables | Exploitation statusNot known exploited | FixNot confirmed | Published11/29/2023 | SeverityUnknown |
CVE-2023-23754[20230501] - Core - Open Redirect and XSS within the mfa select | Exploitation statusNot known exploited | FixNot confirmed | Published05/30/2023 | SeverityMedium |
CVE-2023-23755[20230502] - Core - Bruteforce prevention within the mfa screen | Exploitation statusNot known exploited | FixNot confirmed | Published05/30/2023 | SeverityHigh |
CVE-2023-23752[20230201] - Core - Improper access check in webservice endpoints | Exploitation statusKEV | FixNot confirmed | Published02/16/2023 | SeverityMedium |
CVE-2023-23751[20230102] - Core - Missing ACL checks for com_actionlogs | Exploitation statusNot known exploited | FixNot confirmed | Published02/01/2023 | SeverityMedium |
CVE-2023-23750[20230101] - Core - CSRF within post-installation messages | Exploitation statusNot known exploited | FixNot confirmed | Published02/01/2023 | SeverityMedium |
CVE-2022-27914[20221101] - Core - RXSS through reflection of user input in com_media | Exploitation statusNot known exploited | FixNot confirmed | Published11/08/2022 | SeverityUnknown |
CVE-2022-27913[20221002] - Core - RXSS through reflection of user input in headings | Exploitation statusNot confirmed | FixNot confirmed | Published10/25/2022 | SeverityUnknown |
CVE-2022-27912[20221001] - Core - Debug Mode leaks full request payloads including passwords | Exploitation statusNot confirmed | FixNot confirmed | Published10/25/2022 | SeverityUnknown |
CVE-2022-27911[20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check' | Exploitation statusNot confirmed | FixNot confirmed | Published08/31/2022 | SeverityUnknown |
CVE-2022-23801[20220309] - Core - XSS attack vector through SVG | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23800[20220308] - Core - Inadequate content filtering within the filter code | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23799[20220307] - Core - Variable Tampering on JInput $_REQUEST data | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23798[20220306] - Core - Inadequate validation of internal URLs | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23797[20220305] - Core - Inadequate filtering on the selected Ids | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23796[20220304] - Core - Missing input validation within com_fields class inputs | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23795[20220303] - Core - User row are not bound to a authentication mechanism | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23794[20220302] - Core - Path Disclosure within filesystem error messages | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2022-23793[20220301] - Core - Zip Slip within the Tar extractor | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityUnknown |
CVE-2021-26040[20210801] - Core - Insufficient access control for com_media deletion endpoint | Exploitation statusNot confirmed | FixNot confirmed | Published08/24/2021 | SeverityUnknown |
CVE-2021-26039[20210705] - Core - XSS in com_media imagelist | Exploitation statusNot confirmed | FixNot confirmed | Published07/07/2021 | SeverityUnknown |
CVE-2021-26038[20210704] - Core - Privilege escalation through com_installer | Exploitation statusNot confirmed | FixNot confirmed | Published07/07/2021 | SeverityUnknown |
CVE-2021-26037[20210703] - Core - Lack of enforced session termination | Exploitation statusNot confirmed | FixNot confirmed | Published07/07/2021 | SeverityUnknown |
CVE-2021-26036[20210702] - Core - DoS through usergroup table manipulation | Exploitation statusNot confirmed | FixNot confirmed | Published07/07/2021 | SeverityUnknown |
CVE-2021-26035[20210701] - Core - XSS in JForm Rules field | Exploitation statusNot confirmed | FixNot confirmed | Published07/07/2021 | SeverityUnknown |
CVE-2021-26034[20210503] - Core - CSRF in data download endpoints | Exploitation statusNot confirmed | FixNot confirmed | Published05/26/2021 | SeverityUnknown |
CVE-2021-26033[20210502] - Core - CSRF in AJAX reordering endpoint | Exploitation statusNot confirmed | FixNot confirmed | Published05/26/2021 | SeverityUnknown |
CVE-2021-26032[20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUpload | Exploitation statusNot confirmed | FixNot confirmed | Published05/26/2021 | SeverityUnknown |
CVE-2021-26031[20210402] - Core - Inadequate filters on module layout settings | Exploitation statusNot confirmed | FixNot confirmed | Published04/14/2021 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan