Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
171 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
172 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
173 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
174 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
175 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
176 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
177 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
178 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
179 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
180 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
181 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
182 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
183 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
184 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
185 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
186 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
187 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
188 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
189 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
190 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
191 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
192 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
193 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
194 Joomla 13.1 13.1 0 0 0 0
195 Joomla 12.3 12.3 0 0 0 0
196 Joomla 12.1 12.1 0 0 0 0
197 Joomla 11.4 11.4 0 0 0 0
198 Joomla 11.3 11.3 0 0 0 0
199 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
171 6.1
4.3
MEDIUM
Network
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability. CWE-79
Cross-site Scripting
CVE-2017-9934 cpe:2.3:a:joomla:joomla\!:3.7.2:*
cpe:2.3:a:joomla:joomla\!:3.7.1:*
cpe:2.3:a:joomla:joomla\!:3.7.0:*
cpe:2.3:…
2024-11-21 12:37
2017-07-18
Show GitHub Exploit DB Packet Storm
172 7.5
5.0
HIGH
Network
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. CWE-200
Information Exposure
CVE-2017-9933 cpe:2.3:a:joomla:joomla\!:3.7.1:rc2
cpe:2.3:a:joomla:joomla\!:3.7.1:rc1
cpe:2.3:a:joomla:joomla\!:3.7.1:*
cpe:…
2024-11-21 12:37
2017-07-18
Show GitHub Exploit DB Packet Storm
173 9.8
7.5
CRITICAL
Network
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2017-8917 cpe:2.3:a:joomla:joomla\!:3.7.0:* 2024-11-21 12:34
2017-05-18
Show GitHub Exploit DB Packet Storm
174 5.3
5.0
MEDIUM
Network
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting. CWE-200
Information Exposure
CVE-2017-8057 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
175 6.5
4.0
MEDIUM
Network
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2017-7989 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
176 5.3
5.0
MEDIUM
Network
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article. NVD-CWE-noinfo
CVE-2017-7988 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
177 6.1
4.3
MEDIUM
Network
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component. CWE-79
Cross-site Scripting
CVE-2017-7987 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
178 6.1
4.3
MEDIUM
Network
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components. CWE-79
Cross-site Scripting
CVE-2017-7986 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
179 6.1
4.3
MEDIUM
Network
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components. CWE-79
Cross-site Scripting
CVE-2017-7985 cpe:2.3:a:joomla:joomla\!:*:* 1.5.0 3.6.5 2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
180 6.1
4.3
MEDIUM
Network
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component. CWE-79
Cross-site Scripting
CVE-2017-7984 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm