Exposição de Joomla

CMS
1.482
score de exposição
88.994
sites usam
4
em exploração
89
críticos
Análise Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 resultados
CVE-2026-25901MEDIUMJoomla! Core - [20260502] - XSS in com_associationsEPSS 0.2%CVE-2026-71572MEDIUMJoomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-67361MEDIUMJoomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5EPSS 0.2%CVE-2018-25337MEDIUMJoomla JoomOCShop 1.0 Cross-Site Request ForgeryEPSS 0.2%CVE-2026-67358MEDIUMJoomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5EPSS 0.2%CVE-2026-48900MEDIUMJoomla! Core - [20260516] - Incorrect Access Control in com_schedulerEPSS 0.2%CVE-2026-75952MEDIUMJoomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3EPSS 0.2%CVE-2026-77029MEDIUMJoomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66EPSS 0.2%CVE-2025-25225MEDIUMExtension - hikashop.com - Privilege escalation vulnerability Hikashop component version 1.0.0 - 5.1.3 for JoomlaEPSS 0.2%CVE-2026-76610MEDIUMJoomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65EPSS 0.2%CVE-2026-66490MEDIUMJoomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2EPSS 0.2%CVE-2026-78081HIGHJoomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7EPSS 0.2%CVE-2026-67366MEDIUMJoomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11EPSS 0.2%CVE-2026-48905MEDIUMJoomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.EPSS 0.1%CVE-2026-48903MEDIUMJoomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.EPSS 0.1%CVE-2026-65882MEDIUMJoomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1EPSS 0.1%CVE-2026-65946MEDIUMJoomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0EPSS 0.1%CVE-2026-65712MEDIUMJoomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extensionEPSS 0.1%CVE-2026-63281MEDIUMJoomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions managerEPSS 0.1%CVE-2026-64795MEDIUMJoomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensionsEPSS 0.1%