Known Vulnerabilities for Joomla! CMS by Joomla! Project
Listed below are 10 of the newest known vulnerabilities associated with "Joomla! CMS" by "Joomla! Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77992 json | Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment end... | Not Provided | 2026-08-22 | 2026-08-22 |
| CVE-2026-77029 json | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77028 json | Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77027 json | Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the j... | Not Provided | 2026-08-22 | 2026-08-22 |
| CVE-2026-77026 json | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submiss... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-76613 json | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection all... | Not Provided | 2026-08-21 | 2026-08-23 |
| CVE-2026-76612 json | Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76611 json | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76610 json | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-76609 json | Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoin... | Not Provided | 2026-08-22 | 2026-08-22 |