Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Joomla! CMS — Vulnerabilities & Security Advisories 111

All 111 CVE vulnerabilities found in Joomla! CMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common weakness vulnerabilities affecting the Joomla! content management system. It compiles security issues related to the vendor’s core software distribution, focusing on exposure points identified in standard tracking taxonomies. The collection includes reported flaws ranging from injection attacks and cross-site scripting to improper access controls, covering entries published within the last decade up to the current date. By reviewing this aggregated data, users can track the vendor’s advisory history, observe how specific weakness classes have manifested in this popular platform over time, and examine the chronological progression of reported defects. This resource is designed to help security professionals understand the historical context of Joomla!’s security posture without relying on isolated incidents. Readers can correlate vulnerability reports with specific release cycles to identify patterns in coding errors or design flaws that persist across versions. The data provides a comprehensive view of the attack surface associated with the CMS, allowing for better risk assessment and remediation planning. Whether analyzing the frequency of certain error types or investigating the resolution timeline for critical issues, this page offers a structured overview of the product’s vulnerability landscape. It serves as a neutral reference point for researchers and administrators seeking to contextualize current threats within the broader history of the software’s development and maintenance lifecycle.

Vendor: Joomla! Project

CVE IDTitleCVSSSeverityPublished
CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer CWE-79--2026-07-07
CVE-2026-48947 Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints CWE-284--2026-07-07
CVE-2026-48958 Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints CWE-284--2026-07-07
CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates CWE-79--2026-07-07
CVE-2026-48955 Joomla! Core - [20260709] - Incorrect Access Control in com_workflow CWE-284--2026-07-07
CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules CWE-284--2026-07-07
CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints CWE-284--2026-07-07
CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts CWE-79--2026-07-07
CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout CWE-79--2026-07-07
CVE-2026-48948 Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download CWE-284--2026-07-07
CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management CWE-79--2026-07-07
CVE-2026-48954 Joomla! Core - [20260708] - XSS through language overrides CWE-79--2026-07-07
CVE-2026-35221 Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder CWE-89--2026-05-26
CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass CWE-287--2026-05-26
CVE-2026-35220 Joomla! Core - [20260505] - CSRF in user activation endpoint CWE-352--2026-05-26
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter CWE-22--2026-05-26
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags CWE-89--2026-05-26
CVE-2026-40384 Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint CWE-22--2026-05-26
CVE-2026-48897 Joomla! Core - [20260512] - MFA Authentication Bypass CWE-287--2026-05-26
CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations CWE-79--2026-05-26
CVE-2026-48899 Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins CWE-284--2026-05-26
CVE-2026-48900 Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler CWE-284--2026-05-26
CVE-2026-48902 Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links --2026-05-26
CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints CWE-284--2026-05-26
CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules CWE-79--2026-05-26
CVE-2026-48904 Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints CWE-284--2026-05-26
CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links CWE-79--2026-05-26
CVE-2026-48898 Joomla! Core - [20260513] - Privilege escalation through com_users batch task CWE-284--2026-05-26
CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory CWE-79--2026-05-26
CVE-2026-48901 Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects --2026-05-26

All 111 known CVE vulnerabilities affecting Joomla! CMS with full Chinese analysis, references, and POCs where available.