What is the Joomla CNA?
Joomla is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 157 CVE records since 2020.
How many CVEs has Joomla published?
Joomla has published 157 CVE records, including 79 in the last two years.
What is Joomla's CVE data quality grade?
RadicalNotion.AI grades Joomla's CVE data quality as C, with an overall completeness score of 72.5%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (21%), and CWE (68.8%) information.
What products does Joomla publish CVEs for?
Joomla most frequently publishes CVEs for Joomla! CMS, joomla\!, joomla, joomla-cms, JS Jobs component for Joomla.
Which vendors does Joomla cover?
Joomla publishes CVEs across 46 distinct vendors, most often Joomla! Project, joomla, Bitnami, rsjoomla.com, composer.
Is Joomla actively publishing CVEs?
Joomla is currently active, based on 79 CVEs in the last two years.
What is the average severity of Joomla's CVEs?
The average CVSS base score across Joomla's scored CVEs is 7.7.
How many critical CVEs has Joomla published?
Joomla has published 21 critical-severity CVEs and 30 high-severity CVEs.
Are any of Joomla's CVEs in CISA's Known Exploited Vulnerabilities catalog?
Yes. 1 of Joomla's CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning they are confirmed to be exploited in the wild.
What are the most common weakness types in Joomla's CVEs?
Joomla's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')), CWE-284 (Improper Access Control), CWE-434 (Unrestricted Upload of File with Dangerous Type).
How does Joomla rank among CNAs?
By total CVE volume, Joomla ranks #98 of 370 CNAs, and it reports more complete CVE records than 22% of all CNAs.