LIVE · cybersecurity feed
Live wire
vendor

Joomla

19 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical9
High10
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-352239.8criticaljoomla\!An improper access check allows unauthorized access to com_config webservice endpoints.102d ago
CVE-2026-489029.8criticaljoomla\!The password and username reset features created plain http links for https connections if the "Force SSL" flag wa102d ago
CVE-2026-489049.8criticaljoomla\!An improper access check allows privelege escalation through the com_users group editing webservice endpoint.102d ago
CVE-2026-403839.8criticaljoomla\!An improper validation of user-supplied input leads to a local file inclusion vulnerability.102d ago
CVE-2026-352219.8criticaljoomla\!Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.102d ago
CVE-2026-733739.8criticaljoomla\!Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default l18d ago
CVE-2026-352229.8criticaljoomla\!Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.102d ago
CVE-2026-488989.8criticaljoomla\!An improper access check allows privilege escalation through the com_users batch task.102d ago
CVE-2026-488999.8criticaljoomla\!An improper access check allows privilege escalation through the com_users batch task.102d ago
CVE-2026-489578.8highjoomla\!An improper access check allows unauthorized users to access com_privacy datasets.60d ago
CVE-2026-489588.8highjoomla\!An improper access check allows unauthorized users to create custom fields via webservices endpoints.60d ago
CVE-2026-489488.8highjoomla\!An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.60d ago
CVE-2026-715738.3highjoomla\!Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper imple18d ago
CVE-2017-202678.2highcalendar plannerJoomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attac78d ago
CVE-2026-489017.5highjoomla\!The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.102d ago
CVE-2026-488977.5highjoomla\!Insufficient state checks lead to a vector that allows to bypass 2FA checks.102d ago
CVE-2026-733377.5highjoomla\!Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state c18d ago
CVE-2026-488967.5highjoomla\!Insufficient state checks lead to a vector that allows to bypass 2FA checks.102d ago
CVE-2026-403847.5highjoomla\!An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulne102d ago

Filter the full tracker by Joomla

Our coverage of Joomla

CVE-2026-48282critical

U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog

The U.S. CISA has added several vulnerabilities to its catalog of actively exploited flaws. These include a critical path traversal vulnerability in Adobe ColdFusion that allows for unauthenticated code execution, and multiple issues affecting Joomlack Page Builder and JoomShaper SP Page Builder that can lead to unauthorized access and malicious file uploads. Organizations are urged to update affected software immediately.

CVE-2026-48282high

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.