CVE Tools

Mojoomla

22 CVEs tracked since 2025. Since May 2025, none of them reached CISA KEV.

Mojoomla CVEs per month

May 2025 to Jun 2025. Point at a month, or focus the strip and use the arrow keys.
Mojoomla CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-05160
2025-0660

Products

The products that kept showing up in Mojoomla's monthly top three, with their CVEs summed over those months.

  1. Wpams71 month
  2. Hospital Management System61 month
  3. School Management52 months
  4. Wpcrm - Crm For Contact Form CF7 & Woocommerce21 month
  5. Wpgym11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Mojoomla.

  1. CVE-2025-15657WordPress School Management plugin <= 93.1.0 - Insecure Direct Object References (IDOR) vulnerability5.3
  2. CVE-2026-39433WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability6.5
  3. CVE-2025-15656WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerability8.8
  4. CVE-2025-15655WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability7.6
  5. CVE-2025-32303WordPress WPCHURCH plugin <= 2.7.0 - SQL Injection Vulnerability9.3
  6. CVE-2025-32304WordPress WPCHURCH plugin <= 2.7.0 - Local File Inclusion vulnerability8.1
  7. CVE-2025-31100WordPress School Management Plugin <= 1.93.1 (02-07-2025) - Arbitrary File Upload Vulnerability9.9
  8. CVE-2025-48108WordPress School Management Plugin <= 93.2.0 - Broken Access Control Vulnerability6.5
  9. CVE-2025-32574WordPress WPGYM plugin <= 65.0 - SQL Injection vulnerability8.5
  10. CVE-2025-24774WordPress WPCRM - CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) vulnerability7.1
  11. CVE-2025-47574WordPress School Management System Plugin <= 92.0.0 - Reflected Cross Site Scripting (XSS) vulnerability7.1
  12. CVE-2025-24773WordPress WPCRM - CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - SQL Injection Vulnerability9.3
  13. CVE-2025-32549WordPress WPGYM <= 65.0 - Local File Inclusion Vulnerability7.5
  14. CVE-2025-47572WordPress School Management <= 93.0.0 - Local File Inclusion Vulnerability7.5
  15. CVE-2025-47573WordPress School Management System Plugin <= 92.0.0 - SQL Injection vulnerability9.3

The record

Peak rank
#53 in May 2025
Busiest month shown
May 2025, 16 CVEs
Months with a KEV entry
0 since May 2025
Monthly snapshots
2 since 2025
Mojoomla's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store