CVE Tools

Joomla-project

90 CVEs tracked since 2020. Since Dec 2020, none of them reached CISA KEV.

Joomla-project CVEs per month

Dec 2020 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Joomla-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-1270
2021-0130
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-0530
2021-06null or fewer
2021-0750
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-0390
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-0250
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-0750
2024-0850
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0460
2026-05200
2026-06null or fewer
2026-07120
2026-08100

Products

The products that kept showing up in Joomla-project's monthly top three, with their CVEs summed over those months.

  1. Joomla! CMS8812 months
  2. Joomla! Framework Filter Package21 month
  3. Joomla! Framework Filesystem Package11 month
  4. Joomla/filesystem11 month
  5. Joomla/input11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Joomla-project.

  1. CVE-2026-71573Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.28.3
  2. CVE-2026-72531Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.25.4
  3. CVE-2026-73336Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.26.4
  4. CVE-2026-73372Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.24.3
  5. CVE-2026-71572Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.25.4
  6. CVE-2026-73337Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.27.5
  7. CVE-2026-73371Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.24.3
  8. CVE-2026-72532Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.25.4
  9. CVE-2026-73373Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.29.8
  10. CVE-2026-71574Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.26.5
  11. CVE-2026-48952Joomla! Core - [20260706] - XSS in com_installer6.1
  12. CVE-2026-48947Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints4.9
  13. CVE-2026-48958Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints8.8
  14. CVE-2026-48950Joomla! Core - [20260704] - XSS in com_templates6.1
  15. CVE-2026-48955Joomla! Core - [20260709] - Incorrect Access Control in com_workflow6.5

The record

Peak rank
#61 in May 2026
Busiest month shown
May 2026, 20 CVEs
Months with a KEV entry
0 since Dec 2020
Monthly snapshots
12 since 2020
Joomla-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store