Exposure of Joomla

CMS
1,482
exposure score
88,994
sites use
4
exploited
89
critical
Vexday analysis

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 results
CVE-2026-63047HIGHJoomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1EPSS 0.4%CVE-2026-21625MEDIUMExtension - stackideas.com - Lack of mime type validation in EasyDiscuss component 1.0.0-5.0.15 for JoomlaEPSS 0.4%CVE-2026-66494HIGHJoomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0EPSS 0.4%CVE-2026-60033MEDIUMJoomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0EPSS 0.4%CVE-2025-50056MEDIUMExtension - rsjoomla.com - Reflected XSS vulnerability RSMail! component 1.19.20-1.22.28 for JoomlaEPSS 0.4%CVE-2025-50057MEDIUMExtension - rsjoomla.com - DOS vulnerability RSFiles! component 1.16.3-1.17.7 for JoomlaEPSS 0.4%CVE-2025-26855CRITICALExtension - joomcar.net - SQL injection in Articles Calendar 1.0.0 - 1.0.1.0007 for JoomlaEPSS 0.4%CVE-2025-26854CRITICALExtension - joomcar.net - SQL injection in Articles Good Search 1.0.0 - 1.2.4.0011 for JoomlaEPSS 0.4%CVE-2026-67286MEDIUMJoomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0EPSS 0.4%CVE-2026-21626CRITICALExtension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for JoomlaEPSS 0.4%CVE-2022-27913[20221002] - Core - RXSS through reflection of user input in headingsEPSS 0.4%CVE-2026-63048CRITICALJoomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2EPSS 0.4%CVE-2025-54473CRITICALExtension - phoca.cz - Authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for JoomlaEPSS 0.4%CVE-2024-40749HIGH[20250103] - Core - Read ACL violation in multiple core viewsEPSS 0.4%CVE-2026-65431CRITICALJoomla Extension - regularlabs.com - Zipslip in GeoIP extensionEPSS 0.4%CVE-2026-66914CRITICALJoomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1EPSS 0.4%CVE-2026-66491HIGHJoomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3EPSS 0.4%CVE-2026-66493MEDIUMJoomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3EPSS 0.4%CVE-2026-67285CRITICALJoomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0EPSS 0.4%CVE-2023-23756Extension - advcomsys.com - XSS in oneVote component for Joomla <= 1.7.0EPSS 0.4%