Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 268 CRITICAL 30 HIGH 67 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
261 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 3 4 11 0
262 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 3 5 11 0
263 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 3 5 11 0
264 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 3 6 12 0
265 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 3 6 19 0
266 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 6 6 21 0
267 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 7 6 21 0
268 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 5 6 12 0
269 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 14 25 67 0
270 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 16 32 75 0
271 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 18 33 74 1
272 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 22 34 78 0
273 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 22 34 76 0
274 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 22 40 82 0
275 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 21 41 82 0
276 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 21 43 84 0
277 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 17 34 75 0
278 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 17 34 80 0
279 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
280 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
281 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
282 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
283 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
284 Joomla 13.1 13.1 0 0 0 0
285 Joomla 12.3 12.3 0 0 0 0
286 Joomla 12.1 12.1 0 0 0 0
287 Joomla 11.4 11.4 0 0 0 0
288 Joomla 11.3 11.3 0 0 0 0
289 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
261 -
4.3
MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search,… CWE-79
Cross-site Scripting
CVE-2007-4189 cpe:2.3:a:joomla:joomla\!:*:* 1.0.13 2026-04-23 09:35
2007-08-8
Show GitHub Exploit DB Packet Storm
262 -
4.3
MEDIUM CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in… CWE-74
Injection
CVE-2007-4190 cpe:2.3:a:joomla:joomla\!:*:* 1.0.13 2026-04-23 09:35
2007-08-8
Show GitHub Exploit DB Packet Storm
263 -
6.8
MEDIUM Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsVali… CWE-20
 Improper Input Validation 
CVE-2006-4468 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:05
2006-09-1
Show GitHub Exploit DB Packet Storm
264 -
7.5
HIGH Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws." NVD-CWE-noinfo
CVE-2006-4469 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:19
2006-09-1
Show GitHub Exploit DB Packet Storm
265 -
7.5
HIGH Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion. NVD-CWE-noinfo
CVE-2006-4470 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:19
2006-09-1
Show GitHub Exploit DB Packet Storm
266 -
7.5
HIGH Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task. NVD-CWE-noinfo
CVE-2006-4472 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:19
2006-09-1
Show GitHub Exploit DB Packet Storm
267 -
6.5
MEDIUM The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2006-4471 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-4 22:27
2006-09-1
Show GitHub Exploit DB Packet Storm
268 -
5.0
MEDIUM Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots. CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2005-4650 cpe:2.3:a:joomla:joomla\!:1.0.3:* 2024-02-2 12:07
2005-12-31
Show GitHub Exploit DB Packet Storm