Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • PHP
  • オープンソース
  • GPL v2

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
261 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
262 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
263 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
264 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
265 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
266 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
267 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
268 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
269 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
270 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
271 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
272 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
273 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
274 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
275 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
276 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
277 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
278 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
279 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
280 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
281 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
282 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
283 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
284 Joomla 13.1 13.1 0 0 0 0
285 Joomla 12.3 12.3 0 0 0 0
286 Joomla 12.1 12.1 0 0 0 0
287 Joomla 11.4 11.4 0 0 0 0
288 Joomla 11.3 11.3 0 0 0 0
289 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
261 -
5.0
MEDIUM Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request. CWE-200
Information Exposure
CVE-2009-3946 cpe:2.3:a:joomla:joomla\!:1.5.9:*
cpe:2.3:a:joomla:joomla\!:1.5.8:*
cpe:2.3:a:joomla:joomla\!:1.5.7:*
cpe:2.3:…
1.5.14 2026-04-23 09:35
2009-11-17
Show GitHub Exploit DB Packet Storm
262 -
5.5
MEDIUM Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitr… NVD-CWE-noinfo
CVE-2009-3945 cpe:2.3:a:joomla:joomla\!:1.5.9:*
cpe:2.3:a:joomla:joomla\!:1.5.8:*
cpe:2.3:a:joomla:joomla\!:1.5.7:*
cpe:2.3:…
1.5.14 2026-04-23 09:35
2009-11-17
Show GitHub Exploit DB Packet Storm
263 7.5
5.0
HIGH
Network
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an htt… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2008-4122 cpe:2.3:a:joomla:joomla\!:1.5.8:* 2026-04-23 09:35
2008-12-20
Show GitHub Exploit DB Packet Storm
264 -
4.3
MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fie… CWE-79
Cross-site Scripting
CVE-2007-5577 cpe:2.3:a:joomla:joomla\!:*:* 1.0.13 2026-04-23 09:35
2007-10-19
Show GitHub Exploit DB Packet Storm
265 -
9.3
HIGH Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors. CWE-384
 Session Fixation
CVE-2007-4188 cpe:2.3:a:joomla:joomla\!:*:* 1.0.13 2026-04-23 09:35
2007-08-8
Show GitHub Exploit DB Packet Storm
266 -
4.3
MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search,… CWE-79
Cross-site Scripting
CVE-2007-4189 cpe:2.3:a:joomla:joomla\!:*:* 1.0.13 2026-04-23 09:35
2007-08-8
Show GitHub Exploit DB Packet Storm
267 -
4.3
MEDIUM CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in… CWE-74
Injection
CVE-2007-4190 cpe:2.3:a:joomla:joomla\!:*:* 1.0.13 2026-04-23 09:35
2007-08-8
Show GitHub Exploit DB Packet Storm
268 -
6.8
MEDIUM Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsVali… CWE-20
 Improper Input Validation 
CVE-2006-4468 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:05
2006-09-1
Show GitHub Exploit DB Packet Storm
269 -
7.5
HIGH Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws." NVD-CWE-noinfo
CVE-2006-4469 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:19
2006-09-1
Show GitHub Exploit DB Packet Storm
270 -
7.5
HIGH Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion. NVD-CWE-noinfo
CVE-2006-4470 cpe:2.3:a:joomla:joomla\!:*:* 1.0.11 2021-10-2 00:19
2006-09-1
Show GitHub Exploit DB Packet Storm