The Joomla! Project maintains a broadly represented content-management platform that has achieved widespread deployment across a large segment of the web, creating a correspondingly large and high-value attack surface. Its vulnerability disclosures cluster around the core Joomla system and a diverse ecosystem of third-party extensions and components such as BSQ Sitestats, RS Gallery2, and various community-contributed modules, reflecting the platform's extensibility and the challenge of securing a decentralized plugin architecture. The recurring weakness classes—SQL injection, cross-site scripting, path traversal, and code injection—are characteristic of web-application input handling and template rendering, and vulnerabilities in this vendor frequently acquire public exploit code, making disclosed flaws actionable to attackers rapidly. Defenders should approach Joomla instances as requiring prompt patching discipline, maintain vigilant inventory of active extensions, and consider the platform's attack surface when evaluating web-application security baselines. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomla! Project over time
Of all the CVEs published by Joomla! Project as a CNA, 39.1% affect products that Joomla! Project develops as a vendor.
Of all the CVEs published that affect products developed by Joomla! Project, 11.3% are self-published by Joomla! Project as a CNA.
Signals from CVEs in this vendor scope (975 CVEs).
975 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10033CRITICAL The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrar | Dec 30, 2016 | 9.8 | 99 | YES | YES |
CVE-2023-23752MEDIUM An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | Feb 16, 2023 | 5.3 | 98 | YES | YES |
CVE-2017-8917CRITICAL SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | May 17, 2017 | 9.8 | 94 | NO | YES |
CVE-2016-10045CRITICAL The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging impr | Dec 30, 2016 | 9.8 | 91 | NO | YES |
CVE-2015-8562HIGH Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited | Dec 16, 2015 | 7.5 | 91 | NO | YES |
CVE-2015-7297HIGH SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7 | Oct 29, 2015 | 7.5 | 90 | NO | YES |
CVE-2016-8869CRITICAL The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leverag | Nov 4, 2016 | 9.8 | 88 | NO | YES |
CVE-2015-7857HIGH SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to ex | Oct 29, 2015 | 7.5 | 84 | NO | YES |
CVE-2016-8870HIGH The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote a | Nov 4, 2016 | 8.1 | 80 | NO | YES |
CVE-2015-7858HIGH SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7 | Oct 29, 2015 | 7.5 | 80 | NO | YES |
Signals from CVEs in this vendor scope (975 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomla! Project.
Media articles that mention a CVE ID that affects a product developed by Joomla! Project — matched by CVE ID, not by vendor name.