Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • PHP
  • オープンソース
  • GPL v2

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
61 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
62 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
63 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
64 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
65 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
66 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
67 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
68 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
69 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
70 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
71 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
72 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
73 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
74 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
75 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
76 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
77 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
78 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
79 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
80 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
81 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
82 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
83 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
84 Joomla 13.1 13.1 0 0 0 0
85 Joomla 12.3 12.3 0 0 0 0
86 Joomla 12.1 12.1 0 0 0 0
87 Joomla 11.4 11.4 0 0 0 0
88 Joomla 11.3 11.3 0 0 0 0
89 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
61 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. CWE-863
 Incorrect Authorization
CVE-2021-26027 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.25 2024-11-21 14:55
2021-03-5
Show GitHub Exploit DB Packet Storm
62 7.5
5.0
HIGH
Network
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads NVD-CWE-noinfo
CVE-2021-23132 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
63 7.5
5.0
HIGH
Network
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager. CWE-20
 Improper Input Validation 
CVE-2021-23131 cpe:2.3:a:joomla:joomla\!:*:* 3.2.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
64 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. CWE-79
Cross-site Scripting
CVE-2021-23130 cpe:2.3:a:joomla:joomla\!:*:* 2.5.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
65 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues. CWE-79
Cross-site Scripting
CVE-2021-23129 cpe:2.3:a:joomla:joomla\!:*:* 2.5.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
66 9.1
6.4
CRITICAL
Network
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been … NVD-CWE-noinfo
CVE-2021-23128 cpe:2.3:a:joomla:joomla\!:*:* 3.2.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
67 9.1
6.4
CRITICAL
Network
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes. NVD-CWE-noinfo
CVE-2021-23127 cpe:2.3:a:joomla:joomla\!:*:* 3.2.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
68 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret. CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2021-23126 cpe:2.3:a:joomla:joomla\!:*:* 3.2.0 3.9.25 2024-11-21 14:51
2021-03-5
Show GitHub Exploit DB Packet Storm
69 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors. CWE-79
Cross-site Scripting
CVE-2021-23125 cpe:2.3:a:joomla:joomla\!:*:* 3.1.0 3.9.23 2024-11-21 14:51
2021-01-13
Show GitHub Exploit DB Packet Storm
70 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks. CWE-79
Cross-site Scripting
CVE-2021-23124 cpe:2.3:a:joomla:joomla\!:*:* 3.9.0 3.9.23 2024-11-21 14:51
2021-01-13
Show GitHub Exploit DB Packet Storm