CVE security advisories and vulnerability history for joomla-cms by joomla.
168
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
10
Public exploits
With known exploit
6.4
Avg CVSS
2016–2026
Last updated
Overview
joomla joomla-cms has 168 published CVE records since 2016, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 10 have a known public exploit. The average CVSS base score across scored CVEs is 6.4.
This page aggregates every publicly disclosed vulnerability (CVE) affecting joomla joomla-cms, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of joomla joomla-cms's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High5
Medium20
Low0
141 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of joomla joomla-cms's CVEs is confirmed exploited in the wild.
Public exploits
10
10 of joomla joomla-cms's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every joomla joomla-cms version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about joomla joomla-cms vulnerabilities.
How many CVEs does joomla joomla-cms have?
joomla joomla-cms has 168 published CVE records since 2016.
How many joomla joomla-cms CVEs are in CISA KEV?
Yes — 1 of joomla joomla-cms's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for joomla joomla-cms vulnerabilities?
Yes — 10 of joomla joomla-cms's CVEs have a known public exploit.
Which versions of joomla joomla-cms are affected?
513 distinct joomla joomla-cms versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in joomla joomla-cms CVEs?
joomla joomla-cms's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-284 (Improper Access Control), CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')), CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')).
How many critical joomla joomla-cms vulnerabilities are there?
joomla joomla-cms has 2 critical and 5 high-severity CVEs.
What is the average severity of joomla joomla-cms CVEs?
The average CVSS base score across joomla joomla-cms's scored CVEs is 6.4.