Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Joomla Number Of NVD 273 CRITICAL 32 HIGH 70 MEDIUM 169 LOW 2
URL https://www.joomla.org/
Explanation Joomla is an open source Content Management System (CMS).

Each major version is supported for at least four years.

Basically, it is recommended to use the latest version.
Tag
  • GPL v2
  • PHP
  • オープンソース

Add Information URL
No Type Name URL
1 https://downloads.joomla.org/
2 https://www.joomla.org/announcements/release-news/
3 https://docs.joomla.org/Joomla!_CMS_versions
4 http://feeds.joomla.org/JoomlaSecurityNews
5 http://www.joomla.jp/
6 https://developer.joomla.org/roadmap.html
7 https://docs.joomla.org/Release_and_support_cycle
8 https://github.com/joomla

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
81 Joomla 5.1 5.1.4 Aug. 27, 2024 April 16, 2024 5 7 11 0
82 Joomla 5.0 5.0.3 July 9, 2024 Oct. 17, 2023 April 16, 2024 5 8 11 0
83 Joomla 4.4 4.4.13 April 8, 2025 Oct. 17, 2023 Oct. 17, 2025 5 8 11 0
84 Joomla 4.3 4.3.4 Aug. 22, 2023 April 18, 2023 Oct. 17, 2023 5 9 12 0
85 Joomla 4.2 4.4.6 July 9, 2024 Aug. 16, 2022 April 18, 2023 5 9 19 0
86 Joomla 4.1 4.1.5 June 21, 2022 Feb. 15, 2022 Aug. 16, 2022 8 9 21 0
87 Joomla 4.0 4.0.6 Jan. 18, 2022 Aug. 17, 2021 Feb. 15, 2022 9 9 21 0
88 Joomla 3.10 3.10.11 Aug. 16, 2022 Aug. 17, 2021 Aug. 17, 2023 6 6 12 0
89 Joomla 3.9 3.9.28 July 6, 2021 Oct. 30, 2018 Aug. 17, 2023 15 25 67 0
90 Joomla 3.8 3.8.13 Oct. 9, 2018 Sept. 19, 2017 Oct. 30, 2018 17 32 75 0
91 Joomla 3.7 3.7.5 Aug. 17, 2017 April 25, 2017 Sept. 19, 2017 19 33 74 1
92 Joomla 3.6 3.6.5 Dec. 13, 2016 July 12, 2016 April 25, 2017 23 34 78 0
93 Joomla 3.5 3.5.1 April 5, 2016 March 21, 2016 July 12, 2016 23 34 76 0
94 Joomla 3.4 3.4.8 Dec. 24, 2015 Feb. 24, 2015 March 21, 2016 23 40 82 0
95 Joomla 3.3 3.3.4 Sept. 23, 2014 April 20, 2014 Feb. 24, 2015 22 41 82 0
96 Joomla 3.2 3.2.1 Dec. 18, 2014 Nov. 6, 2013 Oct. 31, 2014 22 43 84 0
97 Joomla 3.1 3.1.6 Nov. 6, 2013 April 24, 2013 Dec. 31, 2013 18 34 75 0
98 Joomla 3.0 3.0.3 Feb. 4, 2013 Sept. 27, 2012 May 31, 2013 18 34 80 0
99 Joomla 2.5 2.5.28 Dec. 10, 2014 Jan. 24, 2012 Dec. 31, 2014 13 30 58 0
100 Joomla 1.7 1.7.5 Feb. 2, 2012 July 19, 2011 Feb. 29, 2012 10 17 29 0
101 Joomla 1.6 1.6.6 July 26, 2011 Jan. 10, 2011 Aug. 31, 2011 10 14 30 0
102 Joomla 1.5 1.5.26 March 27, 2012 Jan. 22, 2008 Sept. 30, 2012 11 19 35 1
103 Joomla 1.0 1.0.15 Feb. 21, 2008 Sept. 17, 2005 July 22, 2009 5 15 30 0
104 Joomla 13.1 13.1 0 0 0 0
105 Joomla 12.3 12.3 0 0 0 0
106 Joomla 12.1 12.1 0 0 0 0
107 Joomla 11.4 11.4 0 0 0 0
108 Joomla 11.3 11.3 0 0 0 0
109 Joomla 11.2 11.2 0 0 0 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
81 6.3
6.8
MEDIUM
Network
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. CWE-352
 Origin Validation Error
CVE-2020-15700 cpe:2.3:a:joomla:joomla\!:*:* 3.7.0 3.9.19 2024-11-21 14:06
2020-07-16
Show GitHub Exploit DB Packet Storm
82 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-15699 cpe:2.3:a:joomla:joomla\!:*:* 2.5.0 3.9.19 2024-11-21 14:06
2020-07-16
Show GitHub Exploit DB Packet Storm
83 5.3
5.0
MEDIUM
Network
An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials NVD-CWE-noinfo
CVE-2020-15698 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.19 2024-11-21 14:06
2020-07-16
Show GitHub Exploit DB Packet Storm
84 4.3
4.0
MEDIUM
Network
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-15697 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.19 2024-11-21 14:06
2020-07-16
Show GitHub Exploit DB Packet Storm
85 6.1
4.3
MEDIUM
Network
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. CWE-79
Cross-site Scripting
CVE-2020-15696 cpe:2.3:a:joomla:joomla\!:*:* 3.0.0 3.9.19 2024-11-21 14:06
2020-07-16
Show GitHub Exploit DB Packet Storm
86 6.3
6.8
MEDIUM
Network
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. CWE-352
 Origin Validation Error
CVE-2020-15695 cpe:2.3:a:joomla:joomla\!:*:* 3.9.0 3.9.19 2024-11-21 14:06
2020-07-16
Show GitHub Exploit DB Packet Storm
87 7.5
5.0
HIGH
Network
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users. CWE-281
 Improper Preservation of Permissions
CVE-2020-13763 cpe:2.3:a:joomla:joomla\!:2.5.0:rc1
cpe:2.3:a:joomla:joomla\!:2.5.0:beta2
cpe:2.3:a:joomla:joomla\!:2.5.0:beta1
2.5.1 3.9.19 2024-11-21 14:01
2020-06-3
Show GitHub Exploit DB Packet Storm
88 6.1
4.3
MEDIUM
Network
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. CWE-79
Cross-site Scripting
CVE-2020-13762 cpe:2.3:a:joomla:joomla\!:*:* 3.9.0 3.9.19 2024-11-21 14:01
2020-06-3
Show GitHub Exploit DB Packet Storm
89 6.1
4.3
MEDIUM
Network
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS. CWE-79
Cross-site Scripting
CVE-2020-13761 cpe:2.3:a:joomla:joomla\!:3.0.0:beta1
cpe:2.3:a:joomla:joomla\!:3.0.0:alpha2
cpe:2.3:a:joomla:joomla\!:3.0.0:alph…
3.0.1 3.9.19 2024-11-21 14:01
2020-06-3
Show GitHub Exploit DB Packet Storm
90 8.8
6.8
HIGH
Network
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. CWE-352
 Origin Validation Error
CVE-2020-13760 cpe:2.3:a:joomla:joomla\!:3.7.0:rc4
cpe:2.3:a:joomla:joomla\!:3.7.0:rc3
cpe:2.3:a:joomla:joomla\!:3.7.0:rc2
cp…
3.7.1 3.9.19 2024-11-21 14:01
2020-06-3
Show GitHub Exploit DB Packet Storm