Exposição de Joomla

CMS
1.482
score de exposição
88.994
sites usam
4
em exploração
89
críticos
Análise Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

471 resultados
CVE-2024-40744CRITICALExtension - tassos.gr - Unrestricted file upload in Convert Forms component for Joomla < 4.4.8EPSS 0.5%CVE-2025-22205HIGHExtension - admiror-design-studio.com - Path traversal in the Admiror Gallery 4.x component for JoomlaEPSS 0.5%CVE-2024-21724MEDIUM[20240203] - Core - XSS in media selection fieldsEPSS 0.5%CVE-2024-21722MEDIUM[20240201] - Core - Insufficient session expiration in MFA management viewsEPSS 0.5%CVE-2026-66916MEDIUMJoomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0EPSS 0.5%CVE-2025-22210HIGHExtension - hikashop.com - SQL injection in Hikashop component version 3.3.0 - 5.1.4 for JoomlaEPSS 0.5%CVE-2023-39974Extension - acymailing.com - Exposure of Sensitive Information in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3EPSS 0.5%CVE-2026-40383HIGHJoomla! Core - [20260509] - LFI in HTMLView layout parameterEPSS 0.5%CVE-2021-26034[20210503] - Core - CSRF in data download endpointsEPSS 0.5%CVE-2021-26033[20210502] - Core - CSRF in AJAX reordering endpointEPSS 0.5%CVE-2026-57830HIGHJoomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7EPSS 0.5%CVE-2025-49468HIGHJoomla Extension - nobossextensions.com - SQL injection vulnerability in No Boss Calendar component before 5.0.7 for JoomlaEPSS 0.5%CVE-2026-78082CRITICALJoomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4EPSS 0.5%CVE-2023-54357HIGHJoomla com_booking 2.4.9 Information Disclosure via Account EnumerationEPSS 0.5%CVE-2026-85192CRITICALJoomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0EPSS 0.5%CVE-2026-88856CRITICALJoomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7EPSS 0.5%CVE-2022-27914[20221101] - Core - RXSS through reflection of user input in com_mediaEPSS 0.5%CVE-2025-22213HIGH[20250301] - Core - Malicious file uploads via Media ManagerEPSS 0.5%CVE-2025-25226CRITICAL[20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database packageEPSS 0.5%CVE-2026-88857CRITICALJoomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7EPSS 0.5%