Known Vulnerabilities for Joomla! CMS by Joomla
Listed below are 10 of the newest known vulnerabilities associated with "Joomla! CMS" by "Joomla".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73327 json | Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-67287 json | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-67286 json | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - ... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-67285 json | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauth... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-67284 json | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated u... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-67283 json | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-67282 json | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-66915 json | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitra... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-66914 json | Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated atta... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-66494 json | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenti... | Not Provided | 2026-08-07 | 2026-08-08 |