CVE Tools

Joomla!

409 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Joomla!, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Joomla! CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Joomla! CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-013
2025-021
2025-031
2025-042
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-012
2026-020
2026-030
2026-045
2026-0520
2026-060
2026-0712
2026-0810
2026-090

Severity

How the 409 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical4511%
  • High12029%
  • Medium24059%
  • Low41%

Latest CVEs

The 15 most recently published vulnerabilities affecting Joomla!.

  1. CVE-2026-71573Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.28.3
  2. CVE-2026-72531Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.25.4
  3. CVE-2026-73336Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.26.4
  4. CVE-2026-73372Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.24.3
  5. CVE-2026-71572Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.25.4
  6. CVE-2026-73337Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.27.5
  7. CVE-2026-73371Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.24.3
  8. CVE-2026-72532Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.25.4
  9. CVE-2026-73373Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.29.8
  10. CVE-2026-71574Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.26.5
  11. CVE-2026-48952Joomla! Core - [20260706] - XSS in com_installer6.1
  12. CVE-2026-48947Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints4.9
  13. CVE-2026-48958Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints8.8
  14. CVE-2026-48950Joomla! Core - [20260704] - XSS in com_templates6.1
  15. CVE-2026-48955Joomla! Core - [20260709] - Incorrect Access Control in com_workflow6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store