Joomla
This hub aggregates every CVE we track for Joomla, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
394
CVEs tracked
42
Critical
116
High
2
In CISA KEV
Severity distribution
MEDIUM232HIGH116CRITICAL42LOW4
Monthly trend
0
0
0
0
3
0
0
2
0
0
0
0
0
0
0
0
2
0
0
5
20
0
12
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Joomla.
- CVE-2026-48952Joomla! Core - [20260706] - XSS in com_installer6.1
- CVE-2026-48947Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints4.9
- CVE-2026-48958Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints8.8
- CVE-2026-48950Joomla! Core - [20260704] - XSS in com_templates6.1
- CVE-2026-48955Joomla! Core - [20260709] - Incorrect Access Control in com_workflow6.5
- CVE-2026-48956Joomla! Core - [20260710] - Incorrect Access Control in com_modules5.0
- CVE-2026-48957Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints8.8
- CVE-2026-48951Joomla! Core - [20260705] - XSS in various modalreturn layouts6.1
- CVE-2026-48953Joomla! Core - [20260707] - XSS in the generic image output layout6.1
- CVE-2026-48948Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download8.8
- CVE-2026-48949Joomla! Core - [20260703] - XSS in MFA method management6.1
- CVE-2026-48954Joomla! Core - [20260708] - XSS through language overrides6.1
- CVE-2026-35221Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder9.8
- CVE-2026-48903Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.6.1
- CVE-2026-48896Joomla! Core - [20260511] - MFA Authentication Bypass7.5
Product normalization is registry-driven with AI assist and human review. How it works