Joomla vulnerabilities - every known CVE across core and extensions
Joomla's component-and-module architecture means most disclosed CVEs originate in third-party extensions rather than core. Tracked, scored, and classified as they're published.
Joomla security
A well-established CMS with a large extension ecosystem
Joomla has been around since 2005 and is widely used in government, education, and enterprise publishing. The Joomla Security Strike Team (JSST) has maintained a formal vulnerability disclosure process for many years. They publish security releases with SA-numbered advisories and coordinate with reporters before going public, so administrators get a chance to patch first.
Most Joomla CVEs come from third-party extensions, not Joomla core. Common vulnerability types include SQL injection in custom database queries, cross-site scripting in input fields and templates, path traversal in file management components, PHP object injection through unsafe use of unserialize(), and access control failures in AJAX endpoints that do not check user permissions before running privileged actions.
Joomla core updates can be applied in one click from the admin panel. Extension updates require checking each vendor's release channel separately. The Joomla Extensions Directory links to vendor sites but does not host extension files directly.
CVSS severity guide
Reading the severity scores
Each Joomla CVE has a CVSS 3.x score from 0 to 10. The score reflects how the vulnerability can be reached, how complex the exploit is, what access an attacker needs beforehand, and the impact on confidentiality, integrity, and availability if the attack succeeds.
Search by extension name, vendor, or keyword to find CVEs for specific Joomla components. Click any CVE ID to see the full record with affected version ranges. If your installed version is in the affected range and no patch is listed, contact the extension vendor or temporarily disable the extension.
| CVE ID | Severity | CVSS | Title | Published |
|---|---|---|---|---|
| CVE-2026-66914 | critical | 9.2/10 | Aug 7, 2026 today | |
| CVE-2026-66494 | high | 8.7/10 | Aug 7, 2026 today | |
| CVE-2026-66492 | medium | 6.1/10 | Aug 7, 2026 today | |
| CVE-2026-65947 | — | — | Jul 29, 2026 9d ago | |
| CVE-2026-65888 | critical | 10.0/10 | Jul 29, 2026 9d ago | |
| CVE-2026-65887 | critical | 10.0/10 | Jul 29, 2026 9d ago | |
| CVE-2026-65890 | critical | 9.2/10 | Jul 29, 2026 9d ago | |
| CVE-2026-66489 | — | — | Jul 29, 2026 9d ago | |
| CVE-2026-66488 | — | — | Jul 29, 2026 9d ago | |
| CVE-2026-65889 | critical | 9.2/10 | Jul 29, 2026 9d ago | |
| CVE-2026-66490 | — | — | Jul 29, 2026 9d ago | |
| CVE-2026-65946 | — | — | Jul 29, 2026 9d ago | |
| CVE-2026-65885 | critical | 9.4/10 | Jul 29, 2026 9d ago | |
| CVE-2026-65881 | — | — | Jul 28, 2026 10d ago | |
| CVE-2026-65882 | — | — | Jul 28, 2026 10d ago | |
| CVE-2026-65876 | critical | 9.2/10 | Jul 27, 2026 11d ago | |
| CVE-2026-65877 | high | 8.2/10 | Jul 27, 2026 11d ago | |
| CVE-2026-65879 | — | — | Jul 27, 2026 11d ago | |
| CVE-2026-65766 | critical | 9.2/10 | Jul 27, 2026 11d ago | |
| CVE-2026-65878 | high | 8.3/10 | Jul 27, 2026 11d ago | |
| CVE-2026-65765 | medium | 6.9/10 | Jul 27, 2026 11d ago | |
| CVE-2026-65764 | medium | 5.1/10 | Jul 27, 2026 11d ago | |
| CVE-2026-65762 | medium | 5.1/10 | Jul 23, 2026 15d ago | |
| CVE-2026-65763 | medium | 5.1/10 | Jul 23, 2026 15d ago | |
| CVE-2026-65759 | high | 8.7/10 | Jul 23, 2026 15d ago | |
| CVE-2026-65761 | critical | 9.3/10 | Jul 23, 2026 15d ago | |
| CVE-2026-65760 | critical | 9.2/10 | Jul 23, 2026 15d ago | |
| CVE-2026-65758 | high | 8.2/10 | Jul 23, 2026 15d ago | |
| CVE-2026-65713 | — | — | Jul 23, 2026 15d ago | |
| CVE-2026-64873 | — | — | Jul 23, 2026 15d ago |