Feed live

Joomla vulnerabilities - every known CVE across core and extensions

Joomla's component-and-module architecture means most disclosed CVEs originate in third-party extensions rather than core. Tracked, scored, and classified as they're published.

Total CVEs tracked
349,462
All time
Critical · Active
12,228
CVSS ≥ 9.0
New · 14 days
3,095
Newly disclosed
Feed last synced
2 hrs ago
Data freshness

Joomla security

A well-established CMS with a large extension ecosystem

Joomla has been around since 2005 and is widely used in government, education, and enterprise publishing. The Joomla Security Strike Team (JSST) has maintained a formal vulnerability disclosure process for many years. They publish security releases with SA-numbered advisories and coordinate with reporters before going public, so administrators get a chance to patch first.

Most Joomla CVEs come from third-party extensions, not Joomla core. Common vulnerability types include SQL injection in custom database queries, cross-site scripting in input fields and templates, path traversal in file management components, PHP object injection through unsafe use of unserialize(), and access control failures in AJAX endpoints that do not check user permissions before running privileged actions.

Joomla core updates can be applied in one click from the admin panel. Extension updates require checking each vendor's release channel separately. The Joomla Extensions Directory links to vendor sites but does not host extension files directly.

CVSS severity guide

Reading the severity scores

Each Joomla CVE has a CVSS 3.x score from 0 to 10. The score reflects how the vulnerability can be reached, how complex the exploit is, what access an attacker needs beforehand, and the impact on confidentiality, integrity, and availability if the attack succeeds.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Search by extension name, vendor, or keyword to find CVEs for specific Joomla components. Click any CVE ID to see the full record with affected version ranges. If your installed version is in the affected range and no patch is listed, contact the extension vendor or temporarily disable the extension.

Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-78071 high 7.5/10 Aug 28, 2026 2d ago
CVE-2026-78073 medium 5.3/10 Aug 28, 2026 2d ago
CVE-2026-78072 high 8.7/10 Aug 28, 2026 2d ago
CVE-2026-78070 medium 6.9/10 Aug 28, 2026 2d ago
CVE-2026-77991 critical 9.4/10 Aug 27, 2026 3d ago
CVE-2026-77034 medium 6.9/10 Aug 27, 2026 3d ago
CVE-2026-77990 medium 5.3/10 Aug 27, 2026 3d ago
CVE-2026-77035 medium 5.1/10 Aug 27, 2026 3d ago
CVE-2026-77989 medium 5.3/10 Aug 27, 2026 3d ago
CVE-2026-77998 critical 10.0/10 Aug 25, 2026 5d ago
CVE-2026-66917 high 8.6/10 Aug 22, 2026 8d ago
CVE-2026-76613 high 8.6/10 Aug 21, 2026 9d ago
CVE-2026-77026 medium 6.9/10 Aug 20, 2026 10d ago
CVE-2026-76610 medium 6.9/10 Aug 20, 2026 10d ago
CVE-2026-75948 high 8.6/10 Aug 20, 2026 10d ago
CVE-2026-76564 high 8.6/10 Aug 20, 2026 10d ago
CVE-2026-75952 medium 4.6/10 Aug 19, 2026 11d ago
CVE-2026-75953 Aug 19, 2026 11d ago
CVE-2026-74803 critical 10.0/10 Aug 19, 2026 11d ago
CVE-2026-75114 medium 5.1/10 Aug 19, 2026 11d ago
CVE-2026-74804 critical 9.3/10 Aug 19, 2026 11d ago
CVE-2026-67364 critical 10.0/10 Aug 19, 2026 11d ago
CVE-2026-67363 high 7.7/10 Aug 19, 2026 11d ago
CVE-2026-71574 high 8.5/10 Aug 18, 2026 12d ago
CVE-2026-74251 critical 9.3/10 Aug 16, 2026 14d ago
CVE-2026-67286 medium 6.3/10 Aug 12, 2026 18d ago
CVE-2026-67285 critical 9.2/10 Aug 12, 2026 18d ago
CVE-2026-66915 critical 10.0/10 Aug 10, 2026 20d ago
CVE-2026-66914 critical 9.2/10 Aug 7, 2026 23d ago
CVE-2026-66494 high 8.7/10 Aug 7, 2026 23d ago
Page 1
Prev 1 2