Exposure of Joomla

CMS
986
exposure score
94,953
sites use
4
exploited
58
critical
Vexday analysis

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

332 results
CVE-2023-23752MEDIUM[20230201] - Core - Improper access check in webservice endpointsEPSS 99.8%KEVCVE-2026-48939CRITICALJoomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15EPSS 82.5%KEVCVE-2026-56291CRITICALJoomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1EPSS 76.1%KEVCVE-2026-48907CRITICALJoomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5EPSS 55.9%KEVCVE-2026-48908CRITICALJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2EPSS 88.1%CVE-2026-56290CRITICALJoomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0EPSS 83.3%CVE-2021-26030[20210401] - Core - Escape xss in logo parameter error pagesEPSS 82.3%CVE-2021-23124[20210102] - Core - XSS in mod_breadcrumbs aria-label attributeEPSS 81.3%CVE-2024-21726MEDIUM[20240205] - Core - Inadequate content filtering within the filter codeEPSS 48.8%CVE-2024-21725MEDIUM[20240204] - Core - XSS in mail address outputsEPSS 32.2%CVE-2020-35613[20201104] - Core - SQL injection in com_users list viewEPSS 28.9%CVE-2026-49049HIGHJoomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handlerEPSS 17.7%CVE-2025-22206MEDIUMExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.2 for JoomlaEPSS 9.2%CVE-2012-1563Joomla! before 2.5.3 allows Admin Account Creation.EPSS 8.9%CVE-2026-48909CRITICALJoomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4EPSS 7.6%CVE-2021-23132[20210306] - Core - com_media allowed paths that are not intended for image uploadsEPSS 6.7%CVE-2020-35616[20201107] - Core - Write ACL violation in multiple core viewsEPSS 6.2%CVE-2025-49484HIGHExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.1 for JoomlaEPSS 3.2%CVE-2022-23793[20220301] - Core - Zip Slip within the Tar extractorEPSS 2.0%CVE-2011-1151Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.EPSS 1.9%