Joomla Joomla CMS

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Joomla product.

RSS Feeds for Joomla security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Joomla products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Joomla Sorted by Most Security Vulnerabilities since 2018

Joomla240 vulnerabilities

Joomla Jambook1 vulnerability

Joomla Jim Component1 vulnerability

Joomla Rssxt Component1 vulnerability

Joomla X Shop Component1 vulnerability

By the Year

In 2026 there have been 68 vulnerabilities in Joomla with an average score of 6.8 out of ten. Last year, in 2025 Joomla had 8 security vulnerabilities published. That is, 60 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.47.




Year Vulnerabilities Average Score
2026 68 6.77
2025 8 5.30
2024 15 5.98
2023 6 6.17
2022 13 6.88
2021 28 6.52
2020 33 6.70
2019 29 6.78
2018 24 7.10

It may take a day or so for new Joomla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Joomla Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-90915 Sep 29, 2026
Joomla! Core: Arbitrary Dir Deletion via Cache Purge (v4.0.0-5.4.8,6.0.0-6.1.3) Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.
Joomla
CVE-2026-92226 Sep 29, 2026
Joomla! Core Improper ACL Checks in 4.0.0-5.4.8, 6.0.0-6.1.3 (CVE-2026-92226) Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.
Joomla
CVE-2026-92224 Sep 29, 2026
Joomla! XSS via Link Toolbar (unescaped) v4.0.05.4.8/6.0.06.1.3 Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.
Joomla
CVE-2026-90907 Sep 29, 2026
Joomla! 1.5.0-6.1.3: unauthorized user creation via profile.save Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.
Joomla
CVE-2026-90914 Sep 29, 2026
Joomla! XSS in Generic Media Output Layouts 4.0.0-5.4.8/6.0.0-6.1.3 Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.
Joomla
CVE-2026-92231 Sep 29, 2026
Joomla! XSS via InputFilter HTML5 entity decode mismatch (1.5.0-5.4.8,6.0.0-6.1.3) Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
Joomla
CVE-2026-90918 Sep 29, 2026
XSS in Joomla! 4-6 Mail Templates HTML Mail XSS Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
Joomla
CVE-2026-92222 Sep 29, 2026
Joomla! SSRF via Unvalidated URLs in Core 4.0.0-5.4.8/6.0.0-6.1.3 Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.
Joomla
CVE-2026-92223 Sep 29, 2026
Joomla! Core Workflow ACL Bypass 5.0.0-5.4.8, 6.0.0-6.1.3 Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.
Joomla
CVE-2026-90917 Sep 29, 2026
Joomla! Core - Improper ACL Check on Tagged Items in 4.x5.4.8 Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.
Joomla
CVE-2026-92225 Sep 29, 2026
CVE-2026-92225 Joomla! Core XSS in Module List (4.0.0-5.4.8,6.0.0-6.1.3) Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.
Joomla
CVE-2026-92227 Sep 29, 2026
Joomla MFA Auth Bypass via RememberMe Cookie (4.0.0-5.4.8,6.0.0-6.1.3) Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.
Joomla
CVE-2026-92232 Sep 29, 2026
Joomla! XSS via whitespace in InputFilter (pre-5.4.9, pre-6.1.4) Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.
Joomla
CVE-2026-90916 Sep 29, 2026
Joomla! Improper ACL in Content History Comparison (4.0.0-5.4.8, 6.0.0-6.1.3) Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents.
Joomla
CVE-2026-90913 Sep 29, 2026
Joomla! Improper ACL Checks in Access Level Endpoints (4.0.0-5.4.8, 6.0.0-6.1.3) Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints.
Joomla
CVE-2026-90906 Sep 29, 2026
Joomla! XSS via HTMLHelper::link (1.5.0-5.4.8, 6.0.0-6.1.3) Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper.
Joomla
CVE-2026-71573 Aug 18, 2026
Joomla! CORS origin validation flaw v4-5.4.7 & 6-6.1.2 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
Joomla
CVE-2026-72531 Aug 18, 2026
Joomla! Core Improper ACL in Custom Fields WS Endpoints (v4-5.4.7, 6-6.1.2) Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Joomla
CVE-2026-73336 Aug 18, 2026
Joomla! XSS via schema.org output in 5.1.0-5.4.7/6.0.0-6.1.2 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
Joomla
CVE-2026-73372 Aug 18, 2026
Joomla! Improper ACL: Schema.org Contact Data Injection (5.16.1.2) Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
Joomla
CVE-2026-71572 Aug 18, 2026
Joomla! Core: Header Injection in download views before 5.4.7 & 6.1.2 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.
Joomla
CVE-2026-73337 Aug 18, 2026
Joomla 4-5.4.7/6-6.1.2 MFA Bypass via Insufficient State Checks Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla
CVE-2026-73371 Aug 18, 2026
Joomla! Core 4.0.0-5.4.7/6.0.0-6.1.2 Improper ACL batch copy Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
Joomla
CVE-2026-72532 Aug 18, 2026
Joomla! Core 4.0.0-5.4.7/6.0.0-6.1.2: Improper ACL on Category Webservice Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
Joomla
CVE-2026-73373 Aug 18, 2026
Joomla <6.1.2 - Unrestricted SHTML Upload (LFE) Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
Joomla
CVE-2026-71574 Aug 18, 2026
Joomla! Core < 5.4.7 - Inconsistent ACL Checks on Webservice Mutation Endpoints Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Joomla
CVE-2026-73327 Aug 12, 2026
Joomla 6.1.1 com_joomlaupdate Path Traversal RCE
Joomla
CVE-2026-64792 Jul 22, 2026
Joomla Smart Search indexing flaw exposes privileged content Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrators identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.
Joomla
CVE-2026-48952 Jul 07, 2026
XSS via unescaped output in Joomla com_installer update list view Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Joomla
CVE-2026-48947 Jul 07, 2026
Joomla CMS Media File Overwrite via Improper Access Check An improper access check allows privileged users to overwrite media files without editing permissions.
Joomla
CVE-2026-48958 Jul 07, 2026
CVE-2026-48958: Unauthorized Custom Field Creation in Joomla Webservices An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Joomla
CVE-2026-48950 Jul 07, 2026
XSS in Joomla com_templates File Manager View Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Joomla
CVE-2026-48955 Jul 07, 2026
CVE-2026-48955: Unauthorized Access to Joomla Workflow Stage & Transition Info An improper access check allows unauthorized users to access workflow stage and transition information.
Joomla
CVE-2026-48956 Jul 07, 2026
Joomla Module List Disclosure via Improper Access Check An improper access check allows users to display a list of modules in the frontend.
Joomla
CVE-2026-48957 Jul 07, 2026
Joomla! com_privacy Improper Access Control Bypass An improper access check allows unauthorized users to access com_privacy datasets.
Joomla
CVE-2026-48951 Jul 07, 2026
Joomla XSS via Unescaped Modalreturn Layouts Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Joomla
CVE-2026-48953 Jul 07, 2026
Joomla XSS via unescaped generic image output layout Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Joomla
CVE-2026-48948 Jul 07, 2026
Joomla com_contact Improper Access Check Allows Private vCard Export An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Joomla
CVE-2026-48949 Jul 07, 2026
XSS in Joomla! MFA Management Views Lack of validation leads to an XSS vulnerability in the MFA management views.
Joomla
CVE-2026-48954 Jul 07, 2026
Joomla CMS XSS via Language Override Validation Flaw Improper validation leads to a generic XSS vector in the language override feature.
Joomla
CVE-2026-35221 May 26, 2026
Joomla com_finder SQLi via Improper Filter Clauses Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
Joomla
CVE-2026-48903 May 26, 2026
XSS via inadequate content filtering in Joomla checkAttribute methods Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
Joomla
CVE-2026-48896 May 26, 2026
Joomla 2FA Bypass via Insufficient State Checks Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla
CVE-2026-35220 May 26, 2026
Joomla CSRF Token Bypass in com_users Admin Activation Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
Joomla
CVE-2026-40383 May 26, 2026
Joomla LFI Vulnerability: Improper Input Validation An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Joomla
CVE-2026-35222 May 26, 2026
Joomla com_tags SQL Injection via Order Clause Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
Joomla
CVE-2026-40384 May 26, 2026
Joomla com_media Path Traversal via Unvalidated Search Parameter An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
Joomla
CVE-2026-48905 May 26, 2026
XSS via lack of input filtering in Joomla HTML filter Lack of input filtering leads to an XSS vector in the HTML filter code.
Joomla
CVE-2026-48897 May 26, 2026
Joomla 2FA Bypass via Insufficient State Checks Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Joomla
CVE-2026-25901 May 26, 2026
Joomla Multilingual Associations XSS from Unescaped Output Lack of output escaping leads to a XSS vector in the multilingual associations component.
Joomla
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.