Exposure of Joomla

CMS
1,482
exposure score
88,994
sites use
4
exploited
89
critical
Vexday analysis

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 results
CVE-2026-65766CRITICALJoomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1EPSS 0.2%CVE-2025-27753MEDIUMExtension - rsjoomla.com - A SQLi vulnerability RSMediaGallery component 1.7.4 - 2.1.6 for JoomlaEPSS 0.2%CVE-2025-54296HIGHExtension - mooj.org - Stored XSS vulnerability in ProFiles component 1.0-1.5.0 for JoomlaEPSS 0.2%CVE-2025-54297HIGHExtension - compojoom.com - Stored XSS vulnerability in CComment component 5.0.0-6.1.14 for JoomlaEPSS 0.2%CVE-2026-48899MEDIUMJoomla! Core - [20260515] - Incorrect Access Control in sample data pluginsEPSS 0.2%CVE-2026-65943HIGHJoomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0EPSS 0.2%CVE-2026-75948HIGHJoomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12EPSS 0.2%CVE-2023-23750MEDIUM[20230101] - Core - CSRF within post-installation messagesEPSS 0.2%CVE-2026-63685HIGHJoomla Extension - regularlabs.com - Authorization bypass in DB Replacer extensionEPSS 0.2%CVE-2026-81566MEDIUMJoomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0EPSS 0.2%CVE-2026-78076MEDIUMJoomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10EPSS 0.2%CVE-2026-77035MEDIUMJoomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1EPSS 0.2%CVE-2026-78075MEDIUMJoomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10EPSS 0.2%CVE-2026-77997MEDIUMJoomla Extension - yootheme.com - Authenticated, privileged information disclosure about site modules YOOtheme Pro 1.0.0-5.0.40EPSS 0.2%CVE-2026-77994CRITICALJoomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5EPSS 0.2%CVE-2026-65876CRITICALJoomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0EPSS 0.2%CVE-2026-67365CRITICALJoomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11EPSS 0.2%CVE-2026-81567HIGHJoomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7EPSS 0.2%CVE-2026-65877HIGHJoomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1EPSS 0.2%CVE-2026-63683HIGHJoomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions managerEPSS 0.2%