Exposure of Joomla

CMS
1,482
exposure score
88,994
sites use
4
exploited
89
critical
Vexday analysis

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 results
CVE-2026-67284MEDIUMJoomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Cloud < 2.0.2EPSS 0.2%CVE-2026-77990MEDIUMJoomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1EPSS 0.2%CVE-2026-78083HIGHJoomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4EPSS 0.2%CVE-2026-66489MEDIUMJoomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2EPSS 0.2%CVE-2026-66488MEDIUMJoomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2EPSS 0.2%CVE-2026-64797HIGHJoomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extensionEPSS 0.2%CVE-2026-60025HIGHJoomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0EPSS 0.2%CVE-2026-21623CRITICALExtension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for JoomlaEPSS 0.2%CVE-2026-21624CRITICALExtension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for JoomlaEPSS 0.2%CVE-2026-71574HIGHJoomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2023-54360MEDIUMJoomla JLex Review 6.0.1 Reflected XSS via review_id ParameterEPSS 0.2%CVE-2026-73336MEDIUMJoomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-72531MEDIUMJoomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-72532MEDIUMJoomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-21632MEDIUMJoomla! Core - [20260304] - XSS vectors in various article title outputsEPSS 0.2%CVE-2025-55757MEDIUMExtension - virtuemart.net - XSS in VirtueMart component 1.0.0 - 4.4.10 for JoomlaEPSS 0.2%CVE-2026-78084MEDIUMJoomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4EPSS 0.2%CVE-2026-30894MEDIUMJoomla! Core - [20260503] - XSS in com_contenthistoryEPSS 0.2%CVE-2026-25900MEDIUMJoomla! Core - [20260501] - XSS in feed modulesEPSS 0.2%CVE-2026-30895MEDIUMJoomla! Core - [20260504] - XSS in readmore linksEPSS 0.2%