Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
101 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
102 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
103 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
104 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
105 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
106 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
107 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
108 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
109 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
110 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
111 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
112 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
113 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
114 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
115 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
116 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
117 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
118 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
119 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
120 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
121 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
122 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
123 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
124 Joomla 13.1 13.1 0 0 0 0
125 Joomla 12.3 12.3 0 0 0 0
126 Joomla 12.1 12.1 0 0 0 0
127 Joomla 11.4 11.4 0 0 0 0
128 Joomla 11.3 11.3 0 0 0 0
129 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
101 5.3
5.0
MEDIUM
Network
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2011-4912 cpe:2.3:a:joomla:joomla\!:*:* 1.5.0 1.5.13 2024-11-21 10:33
2020-02-4
Show GitHub Exploit DB Packet Storm
102 7.5
5.0
HIGH
Network
Joomla! 1.7.1 has core information disclosure due to inadequate error checking. CWE-200
Information Exposure
CVE-2011-4937 cpe:2.3:a:joomla:joomla\!:*:* 1.7.2 2024-11-21 10:33
2020-02-4
Show GitHub Exploit DB Packet Storm
103 7.5
5.0
HIGH
Network
Joomla! core 1.7.1 allows information disclosure due to weak encryption CWE-326
Inadequate Encryption Strength
CVE-2011-3629 cpe:2.3:a:joomla:joomla\!:*:* 1.7.2 2024-11-21 10:30
2020-02-4
Show GitHub Exploit DB Packet Storm
104 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs. CWE-79
Cross-site Scripting
CVE-2020-8421 cpe:2.3:a:joomla:joomla\!:*:* 3.9.0 3.9.14 2024-11-21 14:38
2020-01-29
Show GitHub Exploit DB Packet Storm
105 8.8
6.8
HIGH
Network
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability. CWE-352
 Origin Validation Error
CVE-2020-8420 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.15 2024-11-21 14:38
2020-01-29
Show GitHub Exploit DB Packet Storm
106 8.8
6.8
HIGH
Network
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities. CWE-352
 Origin Validation Error
CVE-2020-8419 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.15 2024-11-21 14:38
2020-01-29
Show GitHub Exploit DB Packet Storm
107 5.4
3.5
MEDIUM
Network
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. CWE-79
Cross-site Scripting
CVE-2011-3595 cpe:2.3:a:joomla:joomla\!:*:* 1.7.0 2024-11-21 10:30
2020-01-23
Show GitHub Exploit DB Packet Storm
108 5.3
5.0
MEDIUM
Network
Joomla! 1.5x through 1.5.12: Missing JEXEC Check CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2011-4907 cpe:2.3:a:joomla:joomla\!:*:* 1.5.0 1.5.12 2024-11-21 10:33
2020-01-15
Show GitHub Exploit DB Packet Storm
109 7.5
5.0
HIGH
Network
Joomla! before 2.5.3 allows Admin Account Creation. CWE-269
 Improper Privilege Management
CVE-2012-1563 cpe:2.3:a:joomla:joomla\!:*:* 2.5.3 2024-11-21 10:37
2020-01-15
Show GitHub Exploit DB Packet Storm
110 7.5
5.0
HIGH
Network
Joomla! core before 2.5.3 allows unauthorized password change. CWE-330
 Use of Insufficiently Random Values
CVE-2012-1562 cpe:2.3:a:joomla:joomla\!:*:* 2.5.3 2024-11-21 10:37
2020-01-15
Show GitHub Exploit DB Packet Storm