Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 268 CRITICAL 30 HIGH 67 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
111 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 3 4 11 0
112 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 3 5 11 0
113 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 3 5 11 0
114 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 3 6 12 0
115 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 3 6 19 0
116 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 6 6 21 0
117 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 7 6 21 0
118 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 5 6 12 0
119 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 14 25 67 0
120 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 16 32 75 0
121 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 18 33 74 1
122 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 22 34 78 0
123 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 22 34 76 0
124 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 22 40 82 0
125 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 21 41 82 0
126 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 21 43 84 0
127 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 17 34 75 0
128 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 17 34 80 0
129 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
130 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
131 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
132 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
133 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
134 Joomla 13.1 13.1 0 0 0 0
135 Joomla 12.3 12.3 0 0 0 0
136 Joomla 12.1 12.1 0 0 0 0
137 Joomla 11.4 11.4 0 0 0 0
138 Joomla 11.3 11.3 0 0 0 0
139 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
111 5.3
5.0
MEDIUM
Network
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. NVD-CWE-noinfo
CVE-2019-15028 cpe:2.3:a:joomla:joomla\!:*:* 1.6.2 3.9.11 2024-11-21 13:27
2019-08-14
Show GitHub Exploit DB Packet Storm
112 8.8
6.5
HIGH
Network
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attri… NVD-CWE-noinfo
CVE-2019-14654 cpe:2.3:a:joomla:joomla\!:3.9.8:*
cpe:2.3:a:joomla:joomla\!:3.9.7:rc
cpe:2.3:a:joomla:joomla\!:3.9.7:-
2024-11-21 13:27
2019-08-5
Show GitHub Exploit DB Packet Storm
113 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors. CWE-79
Cross-site Scripting
CVE-2019-12766 cpe:2.3:a:joomla:joomla\!:*:* 3.6.0 3.9.6 2024-11-21 13:23
2019-06-12
Show GitHub Exploit DB Packet Storm
114 9.8
7.5
CRITICAL
Network
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2019-12765 cpe:2.3:a:joomla:joomla\!:*:* 3.9.0 3.9.6 2024-11-21 13:23
2019-06-12
Show GitHub Exploit DB Packet Storm
115 6.5
4.0
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users. NVD-CWE-noinfo
CVE-2019-12764 cpe:2.3:a:joomla:joomla\!:*:* 3.8.13 3.9.7 2024-11-21 13:23
2019-06-12
Show GitHub Exploit DB Packet Storm
116 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector. CWE-79
Cross-site Scripting
CVE-2019-11809 cpe:2.3:a:joomla:joomla\!:*:* 1.7.0 3.9.6 2024-11-21 13:21
2019-05-20
Show GitHub Exploit DB Packet Storm
117 9.8
7.5
CRITICAL
Network
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protec… CWE-22
CWE-502
Path Traversal
 Deserialization of Untrusted Data
CVE-2019-11831 cpe:2.3:a:joomla:joomla\!:*:* 3.9.3 3.9.5 2024-11-21 13:21
2019-05-9
Show GitHub Exploit DB Packet Storm
118 6.1
4.3
MEDIUM
Network
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an e… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2019-11358 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.4 2024-11-21 13:20
2019-04-20
Show GitHub Exploit DB Packet Storm
119 7.5
5.0
HIGH
Network
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users. CWE-306
Missing Authentication for Critical Function
CVE-2019-10946 cpe:2.3:a:joomla:joomla\!:*:* 3.2.0 3.9.4 2024-11-21 13:20
2019-04-11
Show GitHub Exploit DB Packet Storm
120 9.8
7.5
CRITICAL
Network
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory. CWE-22
Path Traversal
CVE-2019-10945 cpe:2.3:a:joomla:joomla\!:*:* 1.5.0 3.9.4 2024-11-21 13:20
2019-04-11
Show GitHub Exploit DB Packet Storm