| Joomla | Number Of NVD | 273 | CRITICAL | 32 | HIGH | 70 | MEDIUM | 169 | LOW | 2 |
| URL | https://www.joomla.org/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Joomla is an open source Content Management System (CMS). Each major version is supported for at least four years. Basically, it is recommended to use the latest version. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://downloads.joomla.org/ | ||
| 2 | https://www.joomla.org/announcements/release-news/ | ||
| 3 | https://docs.joomla.org/Joomla!_CMS_versions | ||
| 4 | http://feeds.joomla.org/JoomlaSecurityNews | ||
| 5 | http://www.joomla.jp/ | ||
| 6 | https://developer.joomla.org/roadmap.html | ||
| 7 | https://docs.joomla.org/Release_and_support_cycle | ||
| 8 | https://github.com/joomla |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 191 | Joomla 5.1 | 5.1.4 | Aug. 27, 2024 | April 16, 2024 | 5 | 7 | 11 | 0 | |||
| 192 | Joomla 5.0 | 5.0.3 | July 9, 2024 | Oct. 17, 2023 | April 16, 2024 | 5 | 8 | 11 | 0 | ||
| 193 | Joomla 4.4 | 4.4.13 | April 8, 2025 | Oct. 17, 2023 | Oct. 17, 2025 | 5 | 8 | 11 | 0 | ||
| 194 | Joomla 4.3 | 4.3.4 | Aug. 22, 2023 | April 18, 2023 | Oct. 17, 2023 | 5 | 9 | 12 | 0 | ||
| 195 | Joomla 4.2 | 4.4.6 | July 9, 2024 | Aug. 16, 2022 | April 18, 2023 | 5 | 9 | 19 | 0 | ||
| 196 | Joomla 4.1 | 4.1.5 | June 21, 2022 | Feb. 15, 2022 | Aug. 16, 2022 | 8 | 9 | 21 | 0 | ||
| 197 | Joomla 4.0 | 4.0.6 | Jan. 18, 2022 | Aug. 17, 2021 | Feb. 15, 2022 | 9 | 9 | 21 | 0 | ||
| 198 | Joomla 3.10 | 3.10.11 | Aug. 16, 2022 | Aug. 17, 2021 | Aug. 17, 2023 | 6 | 6 | 12 | 0 | ||
| 199 | Joomla 3.9 | 3.9.28 | July 6, 2021 | Oct. 30, 2018 | Aug. 17, 2023 | 15 | 25 | 67 | 0 | ||
| 200 | Joomla 3.8 | 3.8.13 | Oct. 9, 2018 | Sept. 19, 2017 | Oct. 30, 2018 | 17 | 32 | 75 | 0 | ||
| 201 | Joomla 3.7 | 3.7.5 | Aug. 17, 2017 | April 25, 2017 | Sept. 19, 2017 | 19 | 33 | 74 | 1 | ||
| 202 | Joomla 3.6 | 3.6.5 | Dec. 13, 2016 | July 12, 2016 | April 25, 2017 | 23 | 34 | 78 | 0 | ||
| 203 | Joomla 3.5 | 3.5.1 | April 5, 2016 | March 21, 2016 | July 12, 2016 | 23 | 34 | 76 | 0 | ||
| 204 | Joomla 3.4 | 3.4.8 | Dec. 24, 2015 | Feb. 24, 2015 | March 21, 2016 | 23 | 40 | 82 | 0 | ||
| 205 | Joomla 3.3 | 3.3.4 | Sept. 23, 2014 | April 20, 2014 | Feb. 24, 2015 | 22 | 41 | 82 | 0 | ||
| 206 | Joomla 3.2 | 3.2.1 | Dec. 18, 2014 | Nov. 6, 2013 | Oct. 31, 2014 | 22 | 43 | 84 | 0 | ||
| 207 | Joomla 3.1 | 3.1.6 | Nov. 6, 2013 | April 24, 2013 | Dec. 31, 2013 | 18 | 34 | 75 | 0 | ||
| 208 | Joomla 3.0 | 3.0.3 | Feb. 4, 2013 | Sept. 27, 2012 | May 31, 2013 | 18 | 34 | 80 | 0 | ||
| 209 | Joomla 2.5 | 2.5.28 | Dec. 10, 2014 | Jan. 24, 2012 | Dec. 31, 2014 | 13 | 30 | 58 | 0 | ||
| 210 | Joomla 1.7 | 1.7.5 | Feb. 2, 2012 | July 19, 2011 | Feb. 29, 2012 | 10 | 17 | 29 | 0 | ||
| 211 | Joomla 1.6 | 1.6.6 | July 26, 2011 | Jan. 10, 2011 | Aug. 31, 2011 | 10 | 14 | 30 | 0 | ||
| 212 | Joomla 1.5 | 1.5.26 | March 27, 2012 | Jan. 22, 2008 | Sept. 30, 2012 | 11 | 19 | 35 | 1 | ||
| 213 | Joomla 1.0 | 1.0.15 | Feb. 21, 2008 | Sept. 17, 2005 | July 22, 2009 | 5 | 15 | 30 | 0 | ||
| 214 | Joomla 13.1 | 13.1 | 0 | 0 | 0 | 0 | |||||
| 215 | Joomla 12.3 | 12.3 | 0 | 0 | 0 | 0 | |||||
| 216 | Joomla 12.1 | 12.1 | 0 | 0 | 0 | 0 | |||||
| 217 | Joomla 11.4 | 11.4 | 0 | 0 | 0 | 0 | |||||
| 218 | Joomla 11.3 | 11.3 | 0 | 0 | 0 | 0 | |||||
| 219 | Joomla 11.2 | 11.2 | 0 | 0 | 0 | 0 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 191 |
- 7.5 |
HIGH | Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors. |
CWE-22 CWE-20 Path Traversal Improper Input Validation |
CVE-2015-8565 |
cpe:2.3:a:joomla:joomla\!:3.4.5:* cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:… |
2024-11-21 11:38 2015-12-17 |
Show | GitHub Exploit DB Packet Storm | ||||
| 192 |
- 7.5 |
HIGH | Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package ar… |
CWE-22 CWE-20 Path Traversal Improper Input Validation |
CVE-2015-8564 |
cpe:2.3:a:joomla:joomla\!:3.4.5:* cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:… |
2024-11-21 11:38 2015-12-17 |
Show | GitHub Exploit DB Packet Storm | ||||
| 193 |
- 6.8 |
MEDIUM | Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecifie… |
CWE-352
Origin Validation Error |
CVE-2015-8563 |
cpe:2.3:a:joomla:joomla\!:3.4.5:* cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:… |
2024-11-21 11:38 2015-12-17 |
Show | GitHub Exploit DB Packet Storm | ||||
| 194 |
- 7.5 |
HIGH | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in Dece… |
CWE-20
Improper Input Validation |
CVE-2015-8562 |
cpe:2.3:a:joomla:joomla\!:3.4.5:* cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:… |
2024-11-21 11:38 2015-12-17 |
Show | GitHub Exploit DB Packet Storm | ||||
| 195 |
- 5.0 |
MEDIUM | The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors. |
CWE-284
Improper Access Control |
CVE-2015-7899 |
cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:a:joomla:joomla\!:3.4.2:* cpe:2.3:… |
2024-11-21 11:37 2015-10-30 |
Show | GitHub Exploit DB Packet Storm | ||||
| 196 |
- 5.0 |
MEDIUM | The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors. |
CWE-200
Information Exposure |
CVE-2015-7859 |
cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:a:joomla:joomla\!:3.4.2:* cpe:2.3:… |
2024-11-21 11:37 2015-10-30 |
Show | GitHub Exploit DB Packet Storm | ||||
| 197 |
- 7.5 |
HIGH | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297. |
CWE-89
SQL Injection |
CVE-2015-7858 |
cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:a:joomla:joomla\!:3.4.2:* cpe:2.3:a:joomla:joomla\!:3.4.1:* cpe:2.3:… |
2024-11-21 11:37 2015-10-30 |
Show | GitHub Exploit DB Packet Storm | ||||
| 198 |
- 7.5 |
HIGH | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL… |
CWE-89
SQL Injection |
CVE-2015-7857 |
cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:a:joomla:joomla\!:3.4.2:* cpe:2.3:… |
2024-11-21 11:37 2015-10-30 |
Show | GitHub Exploit DB Packet Storm | ||||
| 199 |
- 7.5 |
HIGH | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858. |
CWE-89
SQL Injection |
CVE-2015-7297 |
cpe:2.3:a:joomla:joomla\!:3.4.4:* cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:a:joomla:joomla\!:3.4.2:* cpe:2.3:… |
2024-11-21 11:36 2015-10-30 |
Show | GitHub Exploit DB Packet Storm | ||||
| 200 |
- 4.3 |
MEDIUM | Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
CWE-79
Cross-site Scripting |
CVE-2015-6939 |
cpe:2.3:a:joomla:joomla\!:3.4.3:* cpe:2.3:a:joomla:joomla\!:3.4.2:rc1 cpe:2.3:a:joomla:joomla\!:3.4.2:* cpe:2.… |
2024-11-21 11:35 2015-09-19 |
Show | GitHub Exploit DB Packet Storm |