Joomla vulnerabilities - every known CVE across core and extensions
Joomla's component-and-module architecture means most disclosed CVEs originate in third-party extensions rather than core. Tracked, scored, and classified as they're published.
Joomla security
A well-established CMS with a large extension ecosystem
Joomla has been around since 2005 and is widely used in government, education, and enterprise publishing. The Joomla Security Strike Team (JSST) has maintained a formal vulnerability disclosure process for many years. They publish security releases with SA-numbered advisories and coordinate with reporters before going public, so administrators get a chance to patch first.
Most Joomla CVEs come from third-party extensions, not Joomla core. Common vulnerability types include SQL injection in custom database queries, cross-site scripting in input fields and templates, path traversal in file management components, PHP object injection through unsafe use of unserialize(), and access control failures in AJAX endpoints that do not check user permissions before running privileged actions.
Joomla core updates can be applied in one click from the admin panel. Extension updates require checking each vendor's release channel separately. The Joomla Extensions Directory links to vendor sites but does not host extension files directly.
CVSS severity guide
Reading the severity scores
Each Joomla CVE has a CVSS 3.x score from 0 to 10. The score reflects how the vulnerability can be reached, how complex the exploit is, what access an attacker needs beforehand, and the impact on confidentiality, integrity, and availability if the attack succeeds.
Search by extension name, vendor, or keyword to find CVEs for specific Joomla components. Click any CVE ID to see the full record with affected version ranges. If your installed version is in the affected range and no patch is listed, contact the extension vendor or temporarily disable the extension.
| CVE ID | Severity | CVSS | Title | Published |
|---|---|---|---|---|
| CVE-2026-78071 | high | 7.5/10 | Aug 28, 2026 2d ago | |
| CVE-2026-78073 | medium | 5.3/10 | Aug 28, 2026 2d ago | |
| CVE-2026-78072 | high | 8.7/10 | Aug 28, 2026 2d ago | |
| CVE-2026-78070 | medium | 6.9/10 | Aug 28, 2026 2d ago | |
| CVE-2026-77991 | critical | 9.4/10 | Aug 27, 2026 3d ago | |
| CVE-2026-77034 | medium | 6.9/10 | Aug 27, 2026 3d ago | |
| CVE-2026-77990 | medium | 5.3/10 | Aug 27, 2026 3d ago | |
| CVE-2026-77035 | medium | 5.1/10 | Aug 27, 2026 3d ago | |
| CVE-2026-77989 | medium | 5.3/10 | Aug 27, 2026 3d ago | |
| CVE-2026-77998 | critical | 10.0/10 | Aug 25, 2026 5d ago | |
| CVE-2026-66917 | high | 8.6/10 | Aug 22, 2026 8d ago | |
| CVE-2026-76613 | high | 8.6/10 | Aug 21, 2026 9d ago | |
| CVE-2026-77026 | medium | 6.9/10 | Aug 20, 2026 10d ago | |
| CVE-2026-76610 | medium | 6.9/10 | Aug 20, 2026 10d ago | |
| CVE-2026-75948 | high | 8.6/10 | Aug 20, 2026 10d ago | |
| CVE-2026-76564 | high | 8.6/10 | Aug 20, 2026 10d ago | |
| CVE-2026-75952 | medium | 4.6/10 | Aug 19, 2026 11d ago | |
| CVE-2026-75953 | — | — | Aug 19, 2026 11d ago | |
| CVE-2026-74803 | critical | 10.0/10 | Aug 19, 2026 11d ago | |
| CVE-2026-75114 | medium | 5.1/10 | Aug 19, 2026 11d ago | |
| CVE-2026-74804 | critical | 9.3/10 | Aug 19, 2026 11d ago | |
| CVE-2026-67364 | critical | 10.0/10 | Aug 19, 2026 11d ago | |
| CVE-2026-67363 | high | 7.7/10 | Aug 19, 2026 11d ago | |
| CVE-2026-71574 | high | 8.5/10 | Aug 18, 2026 12d ago | |
| CVE-2026-74251 | critical | 9.3/10 | Aug 16, 2026 14d ago | |
| CVE-2026-67286 | medium | 6.3/10 | Aug 12, 2026 18d ago | |
| CVE-2026-67285 | critical | 9.2/10 | Aug 12, 2026 18d ago | |
| CVE-2026-66915 | critical | 10.0/10 | Aug 10, 2026 20d ago | |
| CVE-2026-66914 | critical | 9.2/10 | Aug 7, 2026 23d ago | |
| CVE-2026-66494 | high | 8.7/10 | Aug 7, 2026 23d ago |