Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 260 CRITICAL 27 HIGH 67 MEDIUM 164 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
231 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 0 4 7 0
232 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 0 5 7 0
233 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 0 5 7 0
234 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 0 6 8 0
235 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 0 6 15 0
236 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 3 6 17 0
237 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 4 6 17 0
238 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 2 6 8 0
239 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 11 25 63 0
240 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 13 32 71 0
241 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 15 33 70 1
242 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 19 34 74 0
243 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 19 34 72 0
244 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 19 40 78 0
245 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 18 41 78 0
246 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 18 43 80 0
247 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 15 34 71 0
248 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 15 34 76 0
249 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
250 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
251 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
252 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
253 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
254 Joomla 13.1 13.1 0 0 0 0
255 Joomla 12.3 12.3 0 0 0 0
256 Joomla 12.1 12.1 0 0 0 0
257 Joomla 11.4 11.4 0 0 0 0
258 Joomla 11.3 11.3 0 0 0 0
259 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
231 -
5.0
MEDIUM Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate filtering" and a "SQL error." NVD-CWE-noinfo
CVE-2012-2748 cpe:2.3:a:joomla:joomla\!:2.5.4:*
cpe:2.3:a:joomla:joomla\!:2.5.3:*
cpe:2.3:a:joomla:joomla\!:2.5.2:*
cpe:2.3:…
2024-11-21 10:39
2012-07-4
Show GitHub Exploit DB Packet Storm
232 -
7.5
HIGH Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking." NVD-CWE-noinfo
CVE-2012-2747 cpe:2.3:a:joomla:joomla\!:2.5.4:*
cpe:2.3:a:joomla:joomla\!:2.5.3:*
cpe:2.3:a:joomla:joomla\!:2.5.2:*
cpe:2.3:…
2024-11-21 10:39
2012-07-4
Show GitHub Exploit DB Packet Storm
233 -
4.3
MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2011-4332 cpe:2.3:a:joomla:joomla\!:1.6:rc1
cpe:2.3:a:joomla:joomla\!:1.6:beta9
cpe:2.3:a:joomla:joomla\!:1.6:beta8
cpe:…
1.6.3 2024-11-21 10:32
2011-11-24
Show GitHub Exploit DB Packet Storm
234 -
5.0
MEDIUM The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecified vector… CWE-310
Cryptographic Issues
CVE-2011-4321 cpe:2.3:a:joomla:joomla\!:1.5.9:*
cpe:2.3:a:joomla:joomla\!:1.5.8:*
cpe:2.3:a:joomla:joomla\!:1.5.7:*
cpe:2.3:…
2024-11-21 10:32
2011-11-24
Show GitHub Exploit DB Packet Storm
235 -
5.0
MEDIUM Joomla! 1.6.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libraries/phpmai… CWE-200
Information Exposure
CVE-2011-3747 cpe:2.3:a:joomla:joomla\!:1.6.0:* 2024-11-21 10:31
2011-09-24
Show GitHub Exploit DB Packet Storm
236 -
4.3
MEDIUM Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web … CWE-20
 Improper Input Validation 
CVE-2011-2892 cpe:2.3:a:joomla:joomla\!:1.6:rc1
cpe:2.3:a:joomla:joomla\!:1.6:beta9
cpe:2.3:a:joomla:joomla\!:1.6:beta8
cpe:…
2024-11-21 10:29
2011-07-28
Show GitHub Exploit DB Packet Storm
237 -
5.0
MEDIUM Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a differe… CWE-200
Information Exposure
CVE-2011-2891 cpe:2.3:a:joomla:joomla\!:1.6:rc1
cpe:2.3:a:joomla:joomla\!:1.6:beta9
cpe:2.3:a:joomla:joomla\!:1.6:beta8
cpe:…
2024-11-21 10:29
2011-07-28
Show GitHub Exploit DB Packet Storm
238 -
5.0
MEDIUM The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors involving th… CWE-200
Information Exposure
CVE-2011-2890 cpe:2.3:a:joomla:joomla\!:1.5.9:*
cpe:2.3:a:joomla:joomla\!:1.5.8:*
cpe:2.3:a:joomla:joomla\!:1.5.7:*
cpe:2.3:…
1.5.23 2024-11-21 10:29
2011-07-28
Show GitHub Exploit DB Packet Storm
239 -
5.0
MEDIUM templates/system/error.php in Joomla! before 1.5.23 might allow remote attackers to obtain sensitive information via unspecified vectors that trigger an undefined value of a certain error field, lead… CWE-200
Information Exposure
CVE-2011-2889 cpe:2.3:a:joomla:joomla\!:1.5.9:*
cpe:2.3:a:joomla:joomla\!:1.5.8:*
cpe:2.3:a:joomla:joomla\!:1.5.7:*
cpe:2.3:…
1.5.22 2024-11-21 10:29
2011-07-28
Show GitHub Exploit DB Packet Storm
240 -
4.3
MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable throug… CWE-79
Cross-site Scripting
CVE-2011-2710 cpe:2.3:a:joomla:joomla\!:1.6:rc1
cpe:2.3:a:joomla:joomla\!:1.6:beta9
cpe:2.3:a:joomla:joomla\!:1.6:beta8
cpe:…
1.6.6 2024-11-21 10:28
2011-07-28
Show GitHub Exploit DB Packet Storm