Joomla CMS
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Joomla product.
RSS Feeds for Joomla security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Joomla products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Joomla Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 68 vulnerabilities in Joomla with an average score of 6.8 out of ten. Last year, in 2025 Joomla had 8 security vulnerabilities published. That is, 60 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.47.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 68 | 6.77 |
| 2025 | 8 | 5.30 |
| 2024 | 15 | 5.98 |
| 2023 | 6 | 6.17 |
| 2022 | 13 | 6.88 |
| 2021 | 28 | 6.52 |
| 2020 | 33 | 6.70 |
| 2019 | 29 | 6.78 |
| 2018 | 24 | 7.10 |
It may take a day or so for new Joomla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Joomla Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-90915 | Sep 29, 2026 |
Joomla! Core: Arbitrary Dir Deletion via Cache Purge (v4.0.0-5.4.8,6.0.0-6.1.3)Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions. |
|
| CVE-2026-92226 | Sep 29, 2026 |
Joomla! Core Improper ACL Checks in 4.0.0-5.4.8, 6.0.0-6.1.3 (CVE-2026-92226)Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items. |
|
| CVE-2026-92224 | Sep 29, 2026 |
Joomla! XSS via Link Toolbar (unescaped) v4.0.05.4.8/6.0.06.1.3Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector. |
|
| CVE-2026-90907 | Sep 29, 2026 |
Joomla! 1.5.0-6.1.3: unauthorized user creation via profile.saveJoomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration. |
|
| CVE-2026-90914 | Sep 29, 2026 |
Joomla! XSS in Generic Media Output Layouts 4.0.0-5.4.8/6.0.0-6.1.3Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts. |
|
| CVE-2026-92231 | Sep 29, 2026 |
Joomla! XSS via InputFilter HTML5 entity decode mismatch (1.5.0-5.4.8,6.0.0-6.1.3)Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector. |
|
| CVE-2026-90918 | Sep 29, 2026 |
XSS in Joomla! 4-6 Mail Templates HTML Mail XSSJoomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. |
|
| CVE-2026-92222 | Sep 29, 2026 |
Joomla! SSRF via Unvalidated URLs in Core 4.0.0-5.4.8/6.0.0-6.1.3Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors. |
|
| CVE-2026-92223 | Sep 29, 2026 |
Joomla! Core Workflow ACL Bypass 5.0.0-5.4.8, 6.0.0-6.1.3Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents. |
|
| CVE-2026-90917 | Sep 29, 2026 |
Joomla! Core - Improper ACL Check on Tagged Items in 4.x5.4.8Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories. |
|
| CVE-2026-92225 | Sep 29, 2026 |
CVE-2026-92225 Joomla! Core XSS in Module List (4.0.0-5.4.8,6.0.0-6.1.3)Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector. |
|
| CVE-2026-92227 | Sep 29, 2026 |
Joomla MFA Auth Bypass via RememberMe Cookie (4.0.0-5.4.8,6.0.0-6.1.3)Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability. |
|
| CVE-2026-92232 | Sep 29, 2026 |
Joomla! XSS via whitespace in InputFilter (pre-5.4.9, pre-6.1.4)Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector. |
|
| CVE-2026-90916 | Sep 29, 2026 |
Joomla! Improper ACL in Content History Comparison (4.0.0-5.4.8, 6.0.0-6.1.3)Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents. |
|
| CVE-2026-90913 | Sep 29, 2026 |
Joomla! Improper ACL Checks in Access Level Endpoints (4.0.0-5.4.8, 6.0.0-6.1.3)Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints. |
|
| CVE-2026-90906 | Sep 29, 2026 |
Joomla! XSS via HTMLHelper::link (1.5.0-5.4.8, 6.0.0-6.1.3)Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper. |
|
| CVE-2026-71573 | Aug 18, 2026 |
Joomla! CORS origin validation flaw v4-5.4.7 & 6-6.1.2Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. |
|
| CVE-2026-72531 | Aug 18, 2026 |
Joomla! Core Improper ACL in Custom Fields WS Endpoints (v4-5.4.7, 6-6.1.2)Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. |
|
| CVE-2026-73336 | Aug 18, 2026 |
Joomla! XSS via schema.org output in 5.1.0-5.4.7/6.0.0-6.1.2Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. |
|
| CVE-2026-73372 | Aug 18, 2026 |
Joomla! Improper ACL: Schema.org Contact Data Injection (5.16.1.2)Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. |
|
| CVE-2026-71572 | Aug 18, 2026 |
Joomla! Core: Header Injection in download views before 5.4.7 & 6.1.2Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. |
|
| CVE-2026-73337 | Aug 18, 2026 |
Joomla 4-5.4.7/6-6.1.2 MFA Bypass via Insufficient State ChecksJoomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
|
| CVE-2026-73371 | Aug 18, 2026 |
Joomla! Core 4.0.0-5.4.7/6.0.0-6.1.2 Improper ACL batch copyJoomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. |
|
| CVE-2026-72532 | Aug 18, 2026 |
Joomla! Core 4.0.0-5.4.7/6.0.0-6.1.2: Improper ACL on Category WebserviceJoomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. |
|
| CVE-2026-73373 | Aug 18, 2026 |
Joomla <6.1.2 - Unrestricted SHTML Upload (LFE)Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. |
|
| CVE-2026-71574 | Aug 18, 2026 |
Joomla! Core < 5.4.7 - Inconsistent ACL Checks on Webservice Mutation EndpointsJoomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI. |
|
| CVE-2026-73327 | Aug 12, 2026 |
Joomla 6.1.1 com_joomlaupdate Path Traversal RCE |
|
| CVE-2026-64792 | Jul 22, 2026 |
Joomla Smart Search indexing flaw exposes privileged contentJoomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrators identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors. |
|
| CVE-2026-48952 | Jul 07, 2026 |
XSS via unescaped output in Joomla com_installer update list viewLack of escaping leads to an XSS vulnerability in the update list view of com_installer. |
|
| CVE-2026-48947 | Jul 07, 2026 |
Joomla CMS Media File Overwrite via Improper Access CheckAn improper access check allows privileged users to overwrite media files without editing permissions. |
|
| CVE-2026-48958 | Jul 07, 2026 |
CVE-2026-48958: Unauthorized Custom Field Creation in Joomla WebservicesAn improper access check allows unauthorized users to create custom fields via webservices endpoints. |
|
| CVE-2026-48950 | Jul 07, 2026 |
XSS in Joomla com_templates File Manager ViewLack of escaping leads to an XSS vulnerability in the file management view of com_templates. |
|
| CVE-2026-48955 | Jul 07, 2026 |
CVE-2026-48955: Unauthorized Access to Joomla Workflow Stage & Transition InfoAn improper access check allows unauthorized users to access workflow stage and transition information. |
|
| CVE-2026-48956 | Jul 07, 2026 |
Joomla Module List Disclosure via Improper Access CheckAn improper access check allows users to display a list of modules in the frontend. |
|
| CVE-2026-48957 | Jul 07, 2026 |
Joomla! com_privacy Improper Access Control BypassAn improper access check allows unauthorized users to access com_privacy datasets. |
|
| CVE-2026-48951 | Jul 07, 2026 |
Joomla XSS via Unescaped Modalreturn LayoutsLack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. |
|
| CVE-2026-48953 | Jul 07, 2026 |
Joomla XSS via unescaped generic image output layoutLack of escaping leads to an XSS vulnerability in the generic image output layout. |
|
| CVE-2026-48948 | Jul 07, 2026 |
Joomla com_contact Improper Access Check Allows Private vCard ExportAn improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
|
| CVE-2026-48949 | Jul 07, 2026 |
XSS in Joomla! MFA Management ViewsLack of validation leads to an XSS vulnerability in the MFA management views. |
|
| CVE-2026-48954 | Jul 07, 2026 |
Joomla CMS XSS via Language Override Validation FlawImproper validation leads to a generic XSS vector in the language override feature. |
|
| CVE-2026-35221 | May 26, 2026 |
Joomla com_finder SQLi via Improper Filter ClausesImproperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. |
|
| CVE-2026-48903 | May 26, 2026 |
XSS via inadequate content filtering in Joomla checkAttribute methodsInadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. |
|
| CVE-2026-48896 | May 26, 2026 |
Joomla 2FA Bypass via Insufficient State ChecksInsufficient state checks lead to a vector that allows to bypass 2FA checks. |
|
| CVE-2026-35220 | May 26, 2026 |
Joomla CSRF Token Bypass in com_users Admin ActivationLack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. |
|
| CVE-2026-40383 | May 26, 2026 |
Joomla LFI Vulnerability: Improper Input ValidationAn improper validation of user-supplied input leads to a local file inclusion vulnerability. |
|
| CVE-2026-35222 | May 26, 2026 |
Joomla com_tags SQL Injection via Order ClauseImproperly validated order clauses lead to a SQL injection vulnerability in com_tags. |
|
| CVE-2026-40384 | May 26, 2026 |
Joomla com_media Path Traversal via Unvalidated Search ParameterAn improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. |
|
| CVE-2026-48905 | May 26, 2026 |
XSS via lack of input filtering in Joomla HTML filterLack of input filtering leads to an XSS vector in the HTML filter code. |
|
| CVE-2026-48897 | May 26, 2026 |
Joomla 2FA Bypass via Insufficient State ChecksInsufficient state checks lead to a vector that allows to bypass 2FA checks. |
|
| CVE-2026-25901 | May 26, 2026 |
Joomla Multilingual Associations XSS from Unescaped OutputLack of output escaping leads to a XSS vector in the multilingual associations component. |
|