Known Vulnerabilities for products from Joomla
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Joomla".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73327 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-67287 json | Not Provided | 2026-08-12 | 2026-08-13 | |
| CVE-2026-67286 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-67285 json | Not Provided | 2026-08-12 | 2026-08-13 | |
| CVE-2026-67284 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-67283 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-67282 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-66915 json | Not Provided | 2026-08-10 | 2026-08-12 | |
| CVE-2026-66914 json | Not Provided | 2026-08-07 | 2026-08-07 | |
| CVE-2026-66494 json | Not Provided | 2026-08-07 | 2026-08-08 | |
| CVE-2026-48958 json | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48957 json | An improper access check allows unauthorized users to access com_privacy datasets. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48956 json | An improper access check allows users to display a list of modules in the frontend. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48955 json | An improper access check allows unauthorized users to access workflow stage and transition information. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48954 json | Improper validation leads to a generic XSS vector in the language override feature. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48953 json | Lack of escaping leads to an XSS vulnerability in the generic image output layout. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48952 json | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48951 json | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48950 json | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-48949 json | Lack of validation leads to an XSS vulnerability in the MFA management views. | Not Provided | 2026-07-07 | 2026-07-09 |