Feed live

Joomla vulnerabilities - every known CVE across core and extensions

Joomla's component-and-module architecture means most disclosed CVEs originate in third-party extensions rather than core. Tracked, scored, and classified as they're published.

Total CVEs tracked
344,228
All time
Critical · Active
11,542
CVSS ≥ 9.0
New · 14 days
2,629
Newly disclosed
Feed last synced
1 hr ago
Data freshness

Joomla security

A well-established CMS with a large extension ecosystem

Joomla has been around since 2005 and is widely used in government, education, and enterprise publishing. The Joomla Security Strike Team (JSST) has maintained a formal vulnerability disclosure process for many years. They publish security releases with SA-numbered advisories and coordinate with reporters before going public, so administrators get a chance to patch first.

Most Joomla CVEs come from third-party extensions, not Joomla core. Common vulnerability types include SQL injection in custom database queries, cross-site scripting in input fields and templates, path traversal in file management components, PHP object injection through unsafe use of unserialize(), and access control failures in AJAX endpoints that do not check user permissions before running privileged actions.

Joomla core updates can be applied in one click from the admin panel. Extension updates require checking each vendor's release channel separately. The Joomla Extensions Directory links to vendor sites but does not host extension files directly.

CVSS severity guide

Reading the severity scores

Each Joomla CVE has a CVSS 3.x score from 0 to 10. The score reflects how the vulnerability can be reached, how complex the exploit is, what access an attacker needs beforehand, and the impact on confidentiality, integrity, and availability if the attack succeeds.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Search by extension name, vendor, or keyword to find CVEs for specific Joomla components. Click any CVE ID to see the full record with affected version ranges. If your installed version is in the affected range and no patch is listed, contact the extension vendor or temporarily disable the extension.

Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-66914 critical 9.2/10 Aug 7, 2026 today
CVE-2026-66494 high 8.7/10 Aug 7, 2026 today
CVE-2026-66492 medium 6.1/10 Aug 7, 2026 today
CVE-2026-65947 Jul 29, 2026 9d ago
CVE-2026-65888 critical 10.0/10 Jul 29, 2026 9d ago
CVE-2026-65887 critical 10.0/10 Jul 29, 2026 9d ago
CVE-2026-65890 critical 9.2/10 Jul 29, 2026 9d ago
CVE-2026-66489 Jul 29, 2026 9d ago
CVE-2026-66488 Jul 29, 2026 9d ago
CVE-2026-65889 critical 9.2/10 Jul 29, 2026 9d ago
CVE-2026-66490 Jul 29, 2026 9d ago
CVE-2026-65946 Jul 29, 2026 9d ago
CVE-2026-65885 critical 9.4/10 Jul 29, 2026 9d ago
CVE-2026-65881 Jul 28, 2026 10d ago
CVE-2026-65882 Jul 28, 2026 10d ago
CVE-2026-65876 critical 9.2/10 Jul 27, 2026 11d ago
CVE-2026-65877 high 8.2/10 Jul 27, 2026 11d ago
CVE-2026-65879 Jul 27, 2026 11d ago
CVE-2026-65766 critical 9.2/10 Jul 27, 2026 11d ago
CVE-2026-65878 high 8.3/10 Jul 27, 2026 11d ago
CVE-2026-65765 medium 6.9/10 Jul 27, 2026 11d ago
CVE-2026-65764 medium 5.1/10 Jul 27, 2026 11d ago
CVE-2026-65762 medium 5.1/10 Jul 23, 2026 15d ago
CVE-2026-65763 medium 5.1/10 Jul 23, 2026 15d ago
CVE-2026-65759 high 8.7/10 Jul 23, 2026 15d ago
CVE-2026-65761 critical 9.3/10 Jul 23, 2026 15d ago
CVE-2026-65760 critical 9.2/10 Jul 23, 2026 15d ago
CVE-2026-65758 high 8.2/10 Jul 23, 2026 15d ago
CVE-2026-65713 Jul 23, 2026 15d ago
CVE-2026-64873 Jul 23, 2026 15d ago
Page 1
Prev 1 2