Joomla\! CVE Vulnerabilities

By Joomla20 known vulnerabilities

Critical
8
High
4
Medium
8
Low
0
None
0

All Joomla\! CVEs

CVE-2026-48905
6.1 medium

Lack of input filtering leads to an XSS vector in the HTML filter code.

May 26, 2026
CVE-2026-48904
9.8 critical

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

May 26, 2026
CVE-2026-48903
6.1 medium

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

May 26, 2026
CVE-2026-48902
9.8 critical

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

May 26, 2026
CVE-2026-48901
7.5 high

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

May 26, 2026
CVE-2026-48900
4.3 medium

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

May 26, 2026
CVE-2026-48899
9.8 critical

An improper access check allows privilege escalation through the com_users batch task.

May 26, 2026
CVE-2026-48898
9.8 critical

An improper access check allows privilege escalation through the com_users batch task.

May 26, 2026
CVE-2026-48897
7.5 high

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

May 26, 2026
CVE-2026-48896
7.5 high

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

May 26, 2026
CVE-2026-40384
7.5 high

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

May 26, 2026
CVE-2026-40383
9.8 critical

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

May 26, 2026
CVE-2026-35223
9.8 critical

An improper access check allows unauthorized access to com_config webservice endpoints.

May 26, 2026
CVE-2026-35222
9.8 critical

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

May 26, 2026
CVE-2026-35221
9.8 critical

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

May 26, 2026
CVE-2026-35220
4.3 medium

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

May 26, 2026
CVE-2026-30895
6.1 medium

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

May 26, 2026
CVE-2026-30894
6.1 medium

Lack of output escaping leads to a XSS vector in the content history component.

May 26, 2026
CVE-2026-25901
6.1 medium

Lack of output escaping leads to a XSS vector in the multilingual associations component.

May 26, 2026
CVE-2026-25900
6.1 medium

Lack of output escaping leads to a XSS vector in the feed modules.

May 26, 2026