Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Joomla! Project

First CVE: Nov 23, 2005Active for: 21 yearsTotal CVEs: 975
65.8
VTI Score
TOP TARGET

The Joomla! Project maintains a broadly represented content-management platform that has achieved widespread deployment across a large segment of the web, creating a correspondingly large and high-value attack surface. Its vulnerability disclosures cluster around the core Joomla system and a diverse ecosystem of third-party extensions and components such as BSQ Sitestats, RS Gallery2, and various community-contributed modules, reflecting the platform's extensibility and the challenge of securing a decentralized plugin architecture. The recurring weakness classes—SQL injection, cross-site scripting, path traversal, and code injection—are characteristic of web-application input handling and template rendering, and vulnerabilities in this vendor frequently acquire public exploit code, making disclosed flaws actionable to attackers rapidly. Defenders should approach Joomla instances as requiring prompt patching discipline, maintain vigilant inventory of active extensions, and consider the platform's attack surface when evaluating web-application security baselines. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
975
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Joomla! Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2005
20 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

Self-Reporting Analysis

Of all the CVEs published by Joomla! Project as a CNA, 39.1% affect products that Joomla! Project develops as a vendor.

39.1%
60.9%
Self-reported: 110 (39.1%)
Third-party: 171 (60.9%)

Of all the CVEs published that affect products developed by Joomla! Project, 11.3% are self-published by Joomla! Project as a CNA.

11.3%
88.7%
Self-published: 110 (11.3%)
Other CNAs: 865 (88.7%)

Products(147 total)

Top CVEs

Signals from CVEs in this vendor scope (975 CVEs).

975 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-10033CRITICAL
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrar
Dec 30, 20169.899YESYES
CVE-2023-23752MEDIUM
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Feb 16, 20235.398YESYES
CVE-2017-8917CRITICAL
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
May 17, 20179.894NOYES
CVE-2016-10045CRITICAL
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging impr
Dec 30, 20169.891NOYES
CVE-2015-8562HIGH
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited
Dec 16, 20157.591NOYES
CVE-2015-7297HIGH
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7
Oct 29, 20157.590NOYES
CVE-2016-8869CRITICAL
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leverag
Nov 4, 20169.888NOYES
CVE-2015-7857HIGH
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to ex
Oct 29, 20157.584NOYES
CVE-2016-8870HIGH
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote a
Nov 4, 20168.180NOYES
CVE-2015-7858HIGH
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7
Oct 29, 20157.580NOYES
View all 975 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products975 CVEs
41%
55%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.1%)
Network228 (23.4%)
Unknown746 (76.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low224 (23.0%)
High5 (0.5%)
Unknown746 (76.5%)
User Interaction
None133 (13.6%)
Unknown746 (76.5%)
Required96 (9.8%)
Privileges Required
Low32 (3.3%)
High6 (0.6%)
None191 (19.6%)
Unknown746 (76.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (975 CVEs).

CISA KEV
2 CVEs
0.2% of CVEs· 99th percentile
Metasploit
13 CVEs
1.3% of CVEs· 97th percentile
Nuclei
116 CVEs
11.9% of CVEs· 97th percentile
ExploitDB
545 CVEs
55.9% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Joomla! Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Joomla! Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Joomla! Project's Products

View all 3 CNAs →

Top CWEs