Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 260 CRITICAL 27 HIGH 67 MEDIUM 164 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
11 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 0 4 7 0
12 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 0 5 7 0
13 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 0 5 7 0
14 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 0 6 8 0
15 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 0 6 15 0
16 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 3 6 17 0
17 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 4 6 17 0
18 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 2 6 8 0
19 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 11 25 63 0
20 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 13 32 71 0
21 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 15 33 70 1
22 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 19 34 74 0
23 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 19 34 72 0
24 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 19 40 78 0
25 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 18 41 78 0
26 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 18 43 80 0
27 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 15 34 71 0
28 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 15 34 76 0
29 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
30 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
31 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
32 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
33 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
34 Joomla 13.1 13.1 0 0 0 0
35 Joomla 12.3 12.3 0 0 0 0
36 Joomla 12.1 12.1 0 0 0 0
37 Joomla 11.4 11.4 0 0 0 0
38 Joomla 11.3 11.3 0 0 0 0
39 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
11 5.4
-
MEDIUM
Network
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. CWE-79
Cross-site Scripting
CVE-2024-21730 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0
5.0.0


4.4.6
5.1.2
2024-11-21 17:54
2024-07-10
Show GitHub Exploit DB Packet Storm
12 7.5
-
HIGH
Network
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. NVD-CWE-noinfo
CVE-2023-40626 cpe:2.3:a:joomla:joomla\!:5.0.0:*
cpe:2.3:a:joomla:joomla\!:*:*
4.0.0
1.6.0


4.4.1
3.10.14
2024-11-21 17:19
2023-11-29
Show GitHub Exploit DB Packet Storm
13 7.5
-
HIGH
Network
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2023-23755 cpe:2.3:a:joomla:joomla\!:*:* 4.2.0 4.3.2 2024-11-21 16:46
2023-05-31
Show GitHub Exploit DB Packet Storm
14 6.1
-
MEDIUM
Network
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. CWE-20
CWE-601
 Improper Input Validation 
Open Redirect
CVE-2023-23754 cpe:2.3:a:joomla:joomla\!:*:* 4.2.0 4.3.2 2024-11-21 16:46
2023-05-31
Show GitHub Exploit DB Packet Storm
15 5.3
-
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. NVD-CWE-Other
CVE-2023-23752 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.2.8 2024-11-21 16:46
2023-02-17
Show GitHub Exploit DB Packet Storm
16 4.3
-
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs. CWE-863
 Incorrect Authorization
CVE-2023-23751 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.2.4 2024-11-21 16:46
2023-02-2
Show GitHub Exploit DB Packet Storm
17 6.3
-
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages. CWE-352
 Origin Validation Error
CVE-2023-23750 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.2.6 2024-11-21 16:46
2023-02-2
Show GitHub Exploit DB Packet Storm
18 6.1
-
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media. CWE-79
Cross-site Scripting
CVE-2022-27914 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.2.5 2024-11-21 15:56
2022-11-9
Show GitHub Exploit DB Packet Storm
19 5.3
-
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. CWE-200
Information Exposure
CVE-2022-27912 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.2.3 2024-11-21 15:56
2022-10-26
Show GitHub Exploit DB Packet Storm
20 6.1
-
MEDIUM
Network
An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components. CWE-79
Cross-site Scripting
CVE-2022-27913 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.2.3 2024-11-21 15:56
2022-10-26
Show GitHub Exploit DB Packet Storm