Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
151 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
152 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
153 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
154 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
155 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
156 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
157 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
158 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
159 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
160 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
161 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
162 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
163 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
164 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
165 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
166 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
167 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
168 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
169 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
170 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
171 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
172 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
173 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
174 Joomla 13.1 13.1 0 0 0 0
175 Joomla 12.3 12.3 0 0 0 0
176 Joomla 12.1 12.1 0 0 0 0
177 Joomla 11.4 11.4 0 0 0 0
178 Joomla 11.3 11.3 0 0 0 0
179 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
151 4.7
2.6
MEDIUM
Network
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack o… CWE-79
Cross-site Scripting
CVE-2018-11328 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
152 4.3
4.0
MEDIUM
Network
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission. CWE-200
Information Exposure
CVE-2018-11327 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
153 4.8
3.5
MEDIUM
Network
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of… CWE-79
Cross-site Scripting
CVE-2018-11326 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
154 9.8
5.0
CRITICAL
Network
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and dis… CWE-209
Information Exposure Through an Error Message
CVE-2018-11325 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
155 5.9
4.3
MEDIUM
Network
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was ex… CWE-362
Race Condition
CVE-2018-11324 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
156 8.8
6.5
HIGH
Network
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions. CWE-269
 Improper Privilege Management
CVE-2018-11323 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
157 7.5
6.0
HIGH
Network
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-11322 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
158 6.5
4.0
MEDIUM
Network
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated … CWE-20
 Improper Input Validation 
CVE-2018-11321 cpe:2.3:a:joomla:joomla\!:*:* 3.8.8 2024-11-21 12:43
2018-05-23
Show GitHub Exploit DB Packet Storm
159 8.8
6.5
HIGH
Network
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view. CWE-89
SQL Injection
CVE-2018-8045 cpe:2.3:a:joomla:joomla\!:*:* 3.5.0 3.8.5 2024-11-21 13:13
2018-03-15
Show GitHub Exploit DB Packet Storm
160 6.1
4.3
MEDIUM
Network
In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. CWE-79
Cross-site Scripting
CVE-2018-6380 cpe:2.3:a:joomla:joomla\!:*:* 3.8.4 2024-11-21 13:10
2018-01-31
Show GitHub Exploit DB Packet Storm