Joomla! Project

First CVE: Dec 28, 2020Active for: 6 years
281
CVEs Published
More CVEs Published than 83% of tracked CNAs
40.1
Avg CVEs / Year
More Avg CVEs / Year than 81% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
2.1%
In CISA KEV
Higher KEV Rate than 91% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Joomla! Project as a CNA, 39.1% affect products that Joomla! Project develops as a vendor.

39.1%
60.9%
Self-reported: 110Third-party: 171

Of all the CVEs published that affect products developed by Joomla! Project, 11.3% are self-published by Joomla! Project as a CNA.

11.3%
88.7%
Self-published: 110Published by other CNAs: 865

Trends Over Time

The number and severity of CVEs published by Joomla! Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2020
5 years ago
Most Recent CVE
Jul 23, 2026
2 days ago

Top CVEs

All CVEs published by Joomla! Project as a CNA, regardless of affected vendor or product.

281 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitra
Jun 29, 20269.899YESYES
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary f
Jul 9, 20269.898YESYES
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Jun 5, 20269.898YESYES
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Feb 16, 20235.398YESYES
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Jun 20, 20269.897YESNO
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Jun 20, 20269.889YESNO
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
Apr 14, 20216.165NONO
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Jan 12, 20216.165NONO
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the s
Jun 20, 20269.554NOYES
Inadequate content filtering leads to XSS vulnerabilities in various components.
Feb 29, 20246.548NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA281 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local4 (1.4%)
Network255 (90.7%)
Unknown22 (7.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low254 (90.4%)
High5 (1.8%)
Unknown22 (7.8%)
User Interaction
None164 (58.4%)
Unknown22 (7.8%)
Required78 (27.8%)
Privileges Required
Low33 (11.7%)
High36 (12.8%)
None190 (67.6%)
Unknown22 (7.8%)

Exploit Exposure

Signals from CVEs in this cna scope (281 CVEs).

CISA KEV
6 CVEs
2.1% of CVEs· 91st percentile
Metasploit
1 CVE
0.4% of CVEs· 81st percentile
Nuclei
4 CVEs
1.4% of CVEs· 82nd percentile
ExploitDB
4 CVEs
1.4% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Joomla! Project as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Joomla! Project as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs