Exposição de Joomla

CMS
1.482
score de exposição
88.994
sites usam
4
em exploração
89
críticos
Análise Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 resultados
CVE-2023-54363MEDIUMJoomla Solidres 2.13.3 Reflected XSS via Multiple ParametersEPSS 0.2%CVE-2023-54364MEDIUMJoomla HikaShop 4.7.4 Reflected XSS via Product FilterEPSS 0.2%CVE-2023-54361MEDIUMJoomla iProperty Real Estate 4.1.1 Reflected XSS via filter_keywordEPSS 0.2%CVE-2026-64872MEDIUMJoomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extensionEPSS 0.2%CVE-2026-65713MEDIUMJoomla Extension - regularlabs.com - Insecure path handling in Modals Pro extensionEPSS 0.2%CVE-2024-40745MEDIUMExtension - tassos.gr - Reflected Cross site scripting vulnerability in Convert Forms component for Joomla < 4.4.8EPSS 0.2%CVE-2026-71571HIGHJoomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11EPSS 0.2%CVE-2026-78375HIGHJoomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0EPSS 0.2%CVE-2026-85188MEDIUMJoomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for JoomlaEPSS 0.2%CVE-2025-27754MEDIUMExtension - rsjoomla.com - A stored XSS vulnerability RSBlog! component 1.11.6 - 1.14.4 for JoomlaEPSS 0.2%CVE-2026-21631MEDIUMJoomla! Core - [20260303] - XSS vector in com_associations comparison viewEPSS 0.2%CVE-2025-30084MEDIUMExtension - rsjoomla.com - Reflected XSS vulnerability RSMail! component 1.19.20-1.22.26 for JoomlaEPSS 0.2%CVE-2026-64875MEDIUMJoomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extensionEPSS 0.2%CVE-2026-48897HIGHJoomla! Core - [20260512] - MFA Authentication BypassEPSS 0.2%CVE-2025-63083MEDIUMJoomla! Core - [20260102] - XSS vector in the pagebreak pluginEPSS 0.2%CVE-2025-63082MEDIUMJoomla! Core - [20260101] - Inadequate content filtering for data URLsEPSS 0.2%CVE-2026-73372MEDIUMJoomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2EPSS 0.2%CVE-2026-73371MEDIUMJoomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-78065HIGHJoomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6EPSS 0.2%CVE-2026-82190MEDIUMJoomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7EPSS 0.2%