Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
91 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
92 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
93 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
94 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
95 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
96 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
97 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
98 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
99 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
100 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
101 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
102 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
103 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
104 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
105 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
106 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
107 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
108 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
109 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
110 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
111 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
112 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
113 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
114 Joomla 13.1 13.1 0 0 0 0
115 Joomla 12.3 12.3 0 0 0 0
116 Joomla 12.1 12.1 0 0 0 0
117 Joomla 11.4 11.4 0 0 0 0
118 Joomla 11.3 11.3 0 0 0 0
119 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
91 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups. NVD-CWE-noinfo
CVE-2020-11891 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 3.9.17 2024-11-21 13:58
2020-04-22
Show GitHub Exploit DB Packet Storm
92 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. CWE-20
 Improper Input Validation 
CVE-2020-11890 cpe:2.3:a:joomla:joomla\!:*:* 2.5.0 3.9.17 2024-11-21 13:58
2020-04-22
Show GitHub Exploit DB Packet Storm
93 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups. NVD-CWE-noinfo
CVE-2020-11889 cpe:2.3:a:joomla:joomla\!:*:* 2.5.0 3.9.17 2024-11-21 13:58
2020-04-22
Show GitHub Exploit DB Packet Storm
94 9.8
7.5
CRITICAL
Network
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype. CWE-89
SQL Injection
CVE-2020-10243 cpe:2.3:a:joomla:joomla\!:*:* 1.7.0 3.9.16 2024-11-21 13:55
2020-03-17
Show GitHub Exploit DB Packet Storm
95 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks. CWE-79
Cross-site Scripting
CVE-2020-10242 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.16 2024-11-21 13:55
2020-03-17
Show GitHub Exploit DB Packet Storm
96 8.8
6.8
HIGH
Network
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF. CWE-352
 Origin Validation Error
CVE-2020-10241 cpe:2.3:a:joomla:joomla\!:*:* 3.2.0 3.9.16 2024-11-21 13:55
2020-03-17
Show GitHub Exploit DB Packet Storm
97 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses. CWE-20
 Improper Input Validation 
CVE-2020-10240 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.16 2024-11-21 13:55
2020-03-17
Show GitHub Exploit DB Packet Storm
98 8.8
6.5
HIGH
Network
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users. CWE-863
 Incorrect Authorization
CVE-2020-10239 cpe:2.3:a:joomla:joomla\!:*:* 3.7.0 3.9.16 2024-11-21 13:55
2020-03-17
Show GitHub Exploit DB Packet Storm
99 7.5
5.0
HIGH
Network
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors. CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2020-10238 cpe:2.3:a:joomla:joomla\!:*:* 2.5.0 3.9.16 2024-11-21 13:55
2020-03-17
Show GitHub Exploit DB Packet Storm
100 9.1
6.4
CRITICAL
Network
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. CWE-89
SQL Injection
CVE-2011-1151 cpe:2.3:a:joomla:joomla\!:1.6.0:* 2024-11-21 10:25
2020-02-6
Show GitHub Exploit DB Packet Storm