Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • PHP
  • オープンソース
  • GPL v2

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
181 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
182 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
183 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
184 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
185 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
186 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
187 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
188 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
189 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
190 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
191 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
192 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
193 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
194 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
195 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
196 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
197 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
198 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
199 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
200 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
201 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
202 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
203 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
204 Joomla 13.1 13.1 0 0 0 0
205 Joomla 12.3 12.3 0 0 0 0
206 Joomla 12.1 12.1 0 0 0 0
207 Joomla 11.4 11.4 0 0 0 0
208 Joomla 11.3 11.3 0 0 0 0
209 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
181 5.3
5.0
MEDIUM
Network
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. CWE-200
Information Exposure
CVE-2017-7983 cpe:2.3:a:joomla:joomla\!:3.6.5:*
cpe:2.3:a:joomla:joomla\!:3.6.4:*
cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.…
2024-11-21 12:33
2017-04-26
Show GitHub Exploit DB Packet Storm
182 9.8
7.5
CRITICAL
Network
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors. CWE-255
Credentials Management
CVE-2016-9081 cpe:2.3:a:joomla:joomla\!:3.6.3:rc3
cpe:2.3:a:joomla:joomla\!:3.6.3:rc2
cpe:2.3:a:joomla:joomla\!:3.6.3:rc1
cp…
2024-11-21 12:00
2017-01-24
Show GitHub Exploit DB Packet Storm
183 9.8
7.5
CRITICAL
Network
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (ba… CWE-88
Argument Injection
CVE-2016-10033 cpe:2.3:a:joomla:joomla\!:*:* 1.5.0 3.6.5 2026-04-22 01:27
2016-12-31
Show GitHub Exploit DB Packet Storm
184 9.8
7.5
CRITICAL
Network
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction be… CWE-77
Command Injection
CVE-2016-10045 cpe:2.3:a:joomla:joomla\!:*:* 1.5.0 3.6.5 2024-11-21 11:43
2016-12-31
Show GitHub Exploit DB Packet Storm
185 7.5
5.0
HIGH
Network
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a us… CWE-284
Improper Access Control
CVE-2016-9838 cpe:2.3:a:joomla:joomla\!:*:* 3.6.4 2024-11-21 12:01
2016-12-16
Show GitHub Exploit DB Packet Storm
186 7.5
5.0
HIGH
Network
An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view all… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-9837 cpe:2.3:a:joomla:joomla\!:*:* 3.6.4 2024-11-21 12:01
2016-12-16
Show GitHub Exploit DB Packet Storm
187 9.8
7.5
CRITICAL
Network
The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a u… CWE-284
Improper Access Control
CVE-2016-9836 cpe:2.3:a:joomla:joomla\!:*:* 3.6.4 2024-11-21 12:01
2016-12-6
Show GitHub Exploit DB Packet Storm
188 8.1
6.8
HIGH
Network
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create … CWE-20
 Improper Input Validation 
CVE-2016-8870 cpe:2.3:a:joomla:joomla\!:*:* 3.6.3 2024-11-21 12:00
2016-11-5
Show GitHub Exploit DB Packet Storm
189 9.8
7.5
CRITICAL
Network
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use o… CWE-20
 Improper Input Validation 
CVE-2016-8869 cpe:2.3:a:joomla:joomla\!:*:* 3.6.3 2024-11-21 12:00
2016-11-5
Show GitHub Exploit DB Packet Storm
190 7.3
7.5
HIGH
Network
SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2015-8769 cpe:2.3:a:joomla:joomla\!:3.4.6:*
cpe:2.3:a:joomla:joomla\!:3.4.5:*
cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:…
2024-11-21 11:39
2016-01-13
Show GitHub Exploit DB Packet Storm