Exposición de Joomla

CMS
1482
score de exposición
88.994
sitios usan
4
en explotación
89
críticos
Análisis Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 resultados
CVE-2026-57833HIGHJoomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2EPSS 0.4%CVE-2026-63264MEDIUMJoomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3EPSS 0.4%CVE-2026-65762MEDIUMJoomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0EPSS 0.4%CVE-2026-65763MEDIUMJoomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4EPSS 0.4%CVE-2026-65759HIGHJoomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1EPSS 0.4%CVE-2026-60031MEDIUMJoomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1EPSS 0.4%CVE-2024-21730MEDIUM[20240702] - Core - Self-XSS in fancyselect list field layoutEPSS 0.4%CVE-2026-48948MEDIUMJoomla! Core - [20260702] - Incorrect Access Control in com_contact vcf downloadEPSS 0.4%CVE-2026-48957MEDIUMJoomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpointsEPSS 0.4%CVE-2026-65760CRITICALJoomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1EPSS 0.4%CVE-2024-40748HIGH[20250102] - Core - XSS vector in the id attribute of menu listsEPSS 0.4%CVE-2026-60034CRITICALJoomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0EPSS 0.4%CVE-2026-60028HIGHJoomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1EPSS 0.4%CVE-2026-60029MEDIUMJoomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1EPSS 0.4%CVE-2026-74252HIGHJoomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5EPSS 0.4%CVE-2026-77991CRITICALJoomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1EPSS 0.4%CVE-2026-76604CRITICALJoomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2EPSS 0.4%CVE-2026-76605CRITICALJoomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2EPSS 0.4%CVE-2026-60032CRITICALJoomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0EPSS 0.4%CVE-2025-54298CRITICALExtension - firecoders.com - Stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for JoomlaEPSS 0.4%