Exposure of Joomla

CMS
1,482
exposure score
88,994
sites use
4
exploited
89
critical
Vexday analysis

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 results
CVE-2023-34476Extension - mooj.org - SQLi in Proforms Basic component for Joomla <= 1.6.0EPSS 0.6%CVE-2023-23758Extension - creative-solutions.net - SQLi in Creative Gallery component for Joomla <= 2.2.0EPSS 0.6%CVE-2023-23757Extension - bestaddon.com - SQLi in BA Gallery component for Joomla <= 1.2.0EPSS 0.6%CVE-2022-27911[20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check'EPSS 0.6%CVE-2022-23798[20220306] - Core - Inadequate validation of internal URLsEPSS 0.6%CVE-2022-23801[20220309] - Core - XSS attack vector through SVGEPSS 0.6%CVE-2022-23796[20220304] - Core - Missing input validation within com_fields class inputsEPSS 0.6%CVE-2026-67282CRITICALJoomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8EPSS 0.6%CVE-2026-61425CRITICALJoomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0EPSS 0.6%CVE-2026-49048HIGHJoomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1EPSS 0.6%CVE-2025-30085CRITICALExtension - rsjoomla.com - Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for JoomlaEPSS 0.6%CVE-2023-23755HIGH[20230502] - Core - Bruteforce prevention within the mfa screenEPSS 0.6%CVE-2026-34424CRITICALSmart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access ToolkitEPSS 0.6%CVE-2024-32788MEDIUMWordPress FG Joomla to Wordpress plugin <= 4.20.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%CVE-2026-60024CRITICALJoomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0EPSS 0.5%CVE-2026-57828CRITICALJoomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3EPSS 0.5%CVE-2024-21723MEDIUM[20240202] - Core - Open redirect in installation applicationEPSS 0.5%CVE-2022-27912[20221001] - Core - Debug Mode leaks full request payloads including passwordsEPSS 0.5%CVE-2026-60026HIGHJoomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1EPSS 0.5%CVE-2026-60027HIGHJoomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1EPSS 0.5%