Joomla! cms
This hub aggregates every CVE we track for Joomla! cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
109
CVEs tracked
16
Critical
26
High
1
In CISA KEV
Severity distribution
MEDIUM67HIGH26CRITICAL16
Monthly trend
0
0
0
0
3
1
1
1
0
0
0
0
1
0
0
0
2
0
0
5
18
0
12
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Joomla! cms.
- CVE-2026-48952Joomla! Core - [20260706] - XSS in com_installer6.1
- CVE-2026-48947Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints4.9
- CVE-2026-48958Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints8.8
- CVE-2026-48950Joomla! Core - [20260704] - XSS in com_templates6.1
- CVE-2026-48955Joomla! Core - [20260709] - Incorrect Access Control in com_workflow6.5
- CVE-2026-48956Joomla! Core - [20260710] - Incorrect Access Control in com_modules5.0
- CVE-2026-48957Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints8.8
- CVE-2026-48951Joomla! Core - [20260705] - XSS in various modalreturn layouts6.1
- CVE-2026-48953Joomla! Core - [20260707] - XSS in the generic image output layout6.1
- CVE-2026-48948Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download8.8
- CVE-2026-48949Joomla! Core - [20260703] - XSS in MFA method management6.1
- CVE-2026-48954Joomla! Core - [20260708] - XSS through language overrides6.1
- CVE-2026-35221Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder9.8
- CVE-2026-48896Joomla! Core - [20260511] - MFA Authentication Bypass7.5
- CVE-2026-35220Joomla! Core - [20260505] - CSRF in user activation endpoint4.3
Product normalization is registry-driven with AI assist and human review. How it works