Joomla! Project
First CVE: Dec 28, 2020Active for: 6 years
281
CVEs Published
More CVEs Published than 83% of tracked CNAs
40.1
Avg CVEs / Year
More Avg CVEs / Year than 81% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
2.1%
In CISA KEV
Higher KEV Rate than 91% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Joomla! Project as a CNA, 39.1% affect products that Joomla! Project develops as a vendor.
39.1%
60.9%
Self-reported: 110Third-party: 171
Of all the CVEs published that affect products developed by Joomla! Project, 11.3% are self-published by Joomla! Project as a CNA.
11.3%
88.7%
Self-published: 110Published by other CNAs: 865
Trends Over Time
The number and severity of CVEs published by Joomla! Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2020
5 years ago
Most Recent CVE
Jul 23, 2026
2 days ago
Top CVEs
All CVEs published by Joomla! Project as a CNA, regardless of affected vendor or product.
281 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56290CRITICAL Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitra | Jun 29, 2026 | 9.8 | 99 | YES | YES |
CVE-2026-56291CRITICAL Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary f | Jul 9, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-48907CRITICAL A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | Jun 5, 2026 | 9.8 | 98 | YES | YES |
CVE-2023-23752MEDIUM An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | Feb 16, 2023 | 5.3 | 98 | YES | YES |
CVE-2026-48908CRITICAL A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | Jun 20, 2026 | 9.8 | 97 | YES | NO |
CVE-2026-48939CRITICAL A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | Jun 20, 2026 | 9.8 | 89 | YES | NO |
CVE-2021-26030MEDIUM An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page | Apr 14, 2021 | 6.1 | 65 | NO | NO |
CVE-2021-23124MEDIUM An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks. | Jan 12, 2021 | 6.1 | 65 | NO | NO |
CVE-2026-48909CRITICAL SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the s | Jun 20, 2026 | 9.5 | 54 | NO | YES |
CVE-2024-21726MEDIUM Inadequate content filtering leads to XSS vulnerabilities in various components. | Feb 29, 2024 | 6.5 | 48 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA281 CVEs
46%
23%
22%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local4 (1.4%)
Network255 (90.7%)
Unknown22 (7.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low254 (90.4%)
High5 (1.8%)
Unknown22 (7.8%)
User Interaction
None164 (58.4%)
Unknown22 (7.8%)
Required78 (27.8%)
Privileges Required
Low33 (11.7%)
High36 (12.8%)
None190 (67.6%)
Unknown22 (7.8%)
Exploit Exposure
Signals from CVEs in this cna scope (281 CVEs).
CISA KEV
6 CVEs
2.1% of CVEs· 91st percentile
Metasploit
1 CVE
0.4% of CVEs· 81st percentile
Nuclei
4 CVEs
1.4% of CVEs· 82nd percentile
ExploitDB
4 CVEs
1.4% of CVEs· 85th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Joomla! Project as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Joomla! Project as a CNA — matched by CVE ID, not by organization name.