Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • PHP
  • オープンソース
  • GPL v2

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
191 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
192 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
193 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
194 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
195 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
196 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
197 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
198 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
199 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
200 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
201 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
202 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
203 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
204 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
205 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
206 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
207 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
208 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
209 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
210 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
211 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
212 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
213 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
214 Joomla 13.1 13.1 0 0 0 0
215 Joomla 12.3 12.3 0 0 0 0
216 Joomla 12.1 12.1 0 0 0 0
217 Joomla 11.4 11.4 0 0 0 0
218 Joomla 11.3 11.3 0 0 0 0
219 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
191 -
7.5
HIGH Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors. CWE-22
CWE-20
Path Traversal
 Improper Input Validation 
CVE-2015-8565 cpe:2.3:a:joomla:joomla\!:3.4.5:*
cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:…
2024-11-21 11:38
2015-12-17
Show GitHub Exploit DB Packet Storm
192 -
7.5
HIGH Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package ar… CWE-22
CWE-20
Path Traversal
 Improper Input Validation 
CVE-2015-8564 cpe:2.3:a:joomla:joomla\!:3.4.5:*
cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:…
2024-11-21 11:38
2015-12-17
Show GitHub Exploit DB Packet Storm
193 -
6.8
MEDIUM Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecifie… CWE-352
 Origin Validation Error
CVE-2015-8563 cpe:2.3:a:joomla:joomla\!:3.4.5:*
cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:…
2024-11-21 11:38
2015-12-17
Show GitHub Exploit DB Packet Storm
194 -
7.5
HIGH Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in Dece… CWE-20
 Improper Input Validation 
CVE-2015-8562 cpe:2.3:a:joomla:joomla\!:3.4.5:*
cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:…
2024-11-21 11:38
2015-12-17
Show GitHub Exploit DB Packet Storm
195 -
5.0
MEDIUM The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors. CWE-284
Improper Access Control
CVE-2015-7899 cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:a:joomla:joomla\!:3.4.2:*
cpe:2.3:…
2024-11-21 11:37
2015-10-30
Show GitHub Exploit DB Packet Storm
196 -
5.0
MEDIUM The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors. CWE-200
Information Exposure
CVE-2015-7859 cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:a:joomla:joomla\!:3.4.2:*
cpe:2.3:…
2024-11-21 11:37
2015-10-30
Show GitHub Exploit DB Packet Storm
197 -
7.5
HIGH SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297. CWE-89
SQL Injection
CVE-2015-7858 cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:a:joomla:joomla\!:3.4.2:*
cpe:2.3:a:joomla:joomla\!:3.4.1:*
cpe:2.3:…
2024-11-21 11:37
2015-10-30
Show GitHub Exploit DB Packet Storm
198 -
7.5
HIGH SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL… CWE-89
SQL Injection
CVE-2015-7857 cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:a:joomla:joomla\!:3.4.2:*
cpe:2.3:…
2024-11-21 11:37
2015-10-30
Show GitHub Exploit DB Packet Storm
199 -
7.5
HIGH SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858. CWE-89
SQL Injection
CVE-2015-7297 cpe:2.3:a:joomla:joomla\!:3.4.4:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:a:joomla:joomla\!:3.4.2:*
cpe:2.3:…
2024-11-21 11:36
2015-10-30
Show GitHub Exploit DB Packet Storm
200 -
4.3
MEDIUM Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2015-6939 cpe:2.3:a:joomla:joomla\!:3.4.3:*
cpe:2.3:a:joomla:joomla\!:3.4.2:rc1
cpe:2.3:a:joomla:joomla\!:3.4.2:*
cpe:2.…
2024-11-21 11:35
2015-09-19
Show GitHub Exploit DB Packet Storm