Exposure of Joomla

CMS
1,482
exposure score
88,994
sites use
4
exploited
89
critical
Vexday analysis

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 results
CVE-2024-24837MEDIUMCross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress pluginsEPSS 0.3%CVE-2025-54475HIGHExtension - joomsky.com - SQL injection in JS jobs component version 1.3.2 - 1.4.4 for JoomlaEPSS 0.3%CVE-2025-54477MEDIUMJoomla! Core - [20250902] User-Enumeration in passkey authentication methodEPSS 0.3%CVE-2026-48956MEDIUMJoomla! Core - [20260710] - Incorrect Access Control in com_modulesEPSS 0.3%CVE-2026-76571CRITICALJoomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2EPSS 0.3%CVE-2026-88855HIGHJoomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7EPSS 0.3%CVE-2026-78077HIGHJoomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10EPSS 0.3%CVE-2026-78070MEDIUMJoomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2EPSS 0.3%CVE-2026-64873CRITICALJoomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extensionEPSS 0.3%CVE-2026-48898HIGHJoomla! Core - [20260513] - Privilege escalation through com_users batch taskEPSS 0.3%CVE-2026-79700MEDIUMJoomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0EPSS 0.3%CVE-2026-79701MEDIUMJoomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0EPSS 0.3%CVE-2026-77026MEDIUMJoomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5EPSS 0.3%CVE-2024-27186MEDIUM[20240803] - Core - XSS in HTML Mail TemplatesEPSS 0.3%CVE-2024-40743MEDIUM[20240805] - Core - XSS vectors in Outputfilter::strip* methodsEPSS 0.3%CVE-2026-73337HIGHJoomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2EPSS 0.3%CVE-2024-40746MEDIUMExtension - hikashop.com - Stored cross site scripting vulnerability in Hikashop component for Joomla < 5.1.1EPSS 0.3%CVE-2026-48941MEDIUMJoomla Extension - getk2.org - Unauthenticated folder delete in K2 extension for Joomla < 2.26EPSS 0.3%CVE-2025-49485HIGHExtension - balbooa.com - SQL injection in Balbooa Forms component version 1.0.0 - 2.3.1.1 for JoomlaEPSS 0.3%CVE-2026-82191MEDIUMJoomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7EPSS 0.3%