Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 260 CRITICAL 27 HIGH 67 MEDIUM 164 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
21 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 0 4 7 0
22 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 0 5 7 0
23 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 0 5 7 0
24 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 0 6 8 0
25 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 0 6 15 0
26 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 3 6 17 0
27 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 4 6 17 0
28 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 2 6 8 0
29 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 11 25 63 0
30 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 13 32 71 0
31 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 15 33 70 1
32 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 19 34 74 0
33 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 19 34 72 0
34 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 19 40 78 0
35 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 18 41 78 0
36 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 18 43 80 0
37 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 15 34 71 0
38 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 15 34 76 0
39 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
40 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
41 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
42 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
43 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
44 Joomla 13.1 13.1 0 0 0 0
45 Joomla 12.3 12.3 0 0 0 0
46 Joomla 12.1 12.1 0 0 0 0
47 Joomla 11.4 11.4 0 0 0 0
48 Joomla 11.3 11.3 0 0 0 0
49 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
21 5.3
-
MEDIUM
Network
An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. NVD-CWE-noinfo
CVE-2022-27911 cpe:2.3:a:joomla:joomla\!:4.2.0:* 2024-11-21 15:56
2022-08-31
Show GitHub Exploit DB Packet Storm
22 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media. CWE-79
Cross-site Scripting
CVE-2022-23801 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.1.0 2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
23 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. CWE-79
Cross-site Scripting
CVE-2022-23800 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.1.0 2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
24 9.8
6.8
CRITICAL
Network
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data. NVD-CWE-noinfo
CVE-2022-23799 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0 4.1.0 2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
25 6.1
5.8
MEDIUM
Network
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. CWE-601
Open Redirect
CVE-2022-23798 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0
2.5.0
4.1.0
3.10.6


2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
26 9.8
7.5
CRITICAL
Network
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection. CWE-89
SQL Injection
CVE-2022-23797 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0
3.0.0
4.1.0
3.10.6


2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
27 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields. CWE-79
Cross-site Scripting
CVE-2022-23796 cpe:2.3:a:joomla:joomla\!:*:* 3.7.0 3.10.6 2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
28 9.8
6.8
CRITICAL
Network
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an ac… CWE-287
Improper Authentication
CVE-2022-23795 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0
2.5.0
4.1.0
3.10.6


2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
29 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source … CWE-209
Information Exposure Through an Error Message
CVE-2022-23794 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0
3.0.0
4.1.0
3.10.6


2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm
30 7.5
5.0
HIGH
Network
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. CWE-22
Path Traversal
CVE-2022-23793 cpe:2.3:a:joomla:joomla\!:*:* 4.0.0
3.0.0
4.1.0
3.10.6


2024-11-21 15:49
2022-03-31
Show GitHub Exploit DB Packet Storm