Joomla vulnerabilities - every known CVE across core and extensions
Joomla's component-and-module architecture means most disclosed CVEs originate in third-party extensions rather than core. Tracked, scored, and classified as they're published.
Joomla security
A well-established CMS with a large extension ecosystem
Joomla has been around since 2005 and is widely used in government, education, and enterprise publishing. The Joomla Security Strike Team (JSST) has maintained a formal vulnerability disclosure process for many years. They publish security releases with SA-numbered advisories and coordinate with reporters before going public, so administrators get a chance to patch first.
Most Joomla CVEs come from third-party extensions, not Joomla core. Common vulnerability types include SQL injection in custom database queries, cross-site scripting in input fields and templates, path traversal in file management components, PHP object injection through unsafe use of unserialize(), and access control failures in AJAX endpoints that do not check user permissions before running privileged actions.
Joomla core updates can be applied in one click from the admin panel. Extension updates require checking each vendor's release channel separately. The Joomla Extensions Directory links to vendor sites but does not host extension files directly.
CVSS severity guide
Reading the severity scores
Each Joomla CVE has a CVSS 3.x score from 0 to 10. The score reflects how the vulnerability can be reached, how complex the exploit is, what access an attacker needs beforehand, and the impact on confidentiality, integrity, and availability if the attack succeeds.
Search by extension name, vendor, or keyword to find CVEs for specific Joomla components. Click any CVE ID to see the full record with affected version ranges. If your installed version is in the affected range and no patch is listed, contact the extension vendor or temporarily disable the extension.
| CVE ID | Severity | CVSS | Title | Published |
|---|---|---|---|---|
| CVE-2026-84048 | medium | 6.3/10 | Sep 15, 2026 4d ago | |
| CVE-2026-78085 | medium | 6.9/10 | Sep 10, 2026 9d ago | |
| CVE-2026-78302 | high | 8.6/10 | Sep 10, 2026 9d ago | |
| CVE-2026-78303 | medium | 6.9/10 | Sep 10, 2026 9d ago | |
| CVE-2026-78075 | medium | 5.1/10 | Aug 31, 2026 19d ago | |
| CVE-2026-78076 | medium | 5.1/10 | Aug 31, 2026 19d ago | |
| CVE-2026-78077 | high | 8.6/10 | Aug 31, 2026 19d ago | |
| CVE-2026-78079 | medium | 5.3/10 | Aug 31, 2026 19d ago | |
| CVE-2026-78074 | high | 8.8/10 | Aug 31, 2026 19d ago | |
| CVE-2026-78071 | high | 7.5/10 | Aug 28, 2026 23d ago | |
| CVE-2026-78073 | medium | 5.3/10 | Aug 28, 2026 23d ago | |
| CVE-2026-78072 | high | 8.7/10 | Aug 28, 2026 23d ago | |
| CVE-2026-78070 | medium | 6.9/10 | Aug 28, 2026 23d ago | |
| CVE-2026-77991 | critical | 9.4/10 | Aug 27, 2026 24d ago | |
| CVE-2026-77034 | medium | 6.9/10 | Aug 27, 2026 24d ago | |
| CVE-2026-77990 | medium | 5.3/10 | Aug 27, 2026 24d ago | |
| CVE-2026-77035 | medium | 5.1/10 | Aug 27, 2026 24d ago | |
| CVE-2026-77989 | medium | 5.3/10 | Aug 27, 2026 24d ago | |
| CVE-2026-77998 | critical | 10.0/10 | Aug 25, 2026 25d ago | |
| CVE-2026-77995 | critical | 10.0/10 | Aug 24, 2026 26d ago | |
| CVE-2026-66917 | high | 8.6/10 | Aug 22, 2026 28d ago | |
| CVE-2026-76613 | high | 8.6/10 | Aug 21, 2026 29d ago | |
| CVE-2026-77026 | medium | 6.9/10 | Aug 20, 2026 1mo ago | |
| CVE-2026-76610 | medium | 6.9/10 | Aug 20, 2026 1mo ago | |
| CVE-2026-75948 | high | 8.6/10 | Aug 20, 2026 1mo ago | |
| CVE-2026-76564 | high | 8.6/10 | Aug 20, 2026 1mo ago | |
| CVE-2026-75952 | medium | 4.6/10 | Aug 19, 2026 1mo ago | |
| CVE-2026-75953 | — | — | Aug 19, 2026 1mo ago | |
| CVE-2026-74803 | critical | 10.0/10 | Aug 19, 2026 1mo ago | |
| CVE-2026-75114 | medium | 5.1/10 | Aug 19, 2026 1mo ago |