Joomla! Project Joomla! CMS

17 known vulnerabilities in Joomla! Project Joomla! CMS, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2023-23752 CVSS 5.3 medium · actively exploited Joomla! Improper Access Control Vulnerability

Latest vulnerabilities

  • CVE-2026-92232 CVSS 7.1 high Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8…
  • CVE-2026-92231 CVSS 7.1 high Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 …
  • CVE-2026-92227 CVSS 8.2 high Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature…
  • CVE-2026-92226 CVSS 7.0 high Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper…
  • CVE-2026-92225 CVSS 5.9 medium Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape…
  • CVE-2026-92224 CVSS 5.9 medium Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not…
  • CVE-2026-92223 CVSS 5.1 medium Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access…
  • CVE-2026-92222 CVSS 8.9 high Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside…
  • CVE-2026-90918 CVSS 6.9 medium Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an…
  • CVE-2026-90917 CVSS 6.9 medium Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access…
  • CVE-2026-90916 CVSS 5.1 medium Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper…
  • CVE-2026-90915 CVSS 7.0 high Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper…
  • CVE-2026-90914 CVSS 5.9 medium Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to…
  • CVE-2026-90913 CVSS 7.0 high Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An…
  • CVE-2026-90907 CVSS 6.9 medium Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The…
  • CVE-2026-90906 CVSS 5.9 medium Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS…
  • CVE-2023-23752 CVSS 5.3 medium · actively exploited Joomla! Improper Access Control Vulnerability