Product:

Joomla\!

(Joomla)
Repositories https://github.com/joomla/joomla-cms
#Vulnerabilities 274
Date Id Summary Products Score Patch Annotated
2025-01-07 CVE-2024-40748 Lack of output escaping in the id attribute of menu lists. Joomla\! N/A
2025-01-07 CVE-2024-40747 Various module chromes didn't properly process inputs, leading to XSS vectors. Joomla\! N/A
2025-01-07 CVE-2024-40749 Improper Access Controls allows access to protected views. Joomla\! N/A
2025-04-08 CVE-2025-25226 Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. Joomla\! N/A
2025-04-08 CVE-2025-25227 Insufficient state checks lead to a vector that allows to bypass 2FA checks. Joomla\! N/A
2024-02-29 CVE-2024-21722 The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. Joomla\! N/A
2024-02-29 CVE-2024-21723 Inadequate parsing of URLs could result into an open redirect. Joomla\! N/A
2024-02-29 CVE-2024-21725 Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. Joomla\! N/A
2024-02-29 CVE-2024-21726 Inadequate content filtering leads to XSS vulnerabilities in various components. Joomla\! N/A
2024-07-09 CVE-2024-21730 The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. Joomla\! 5.4