Vulnerabilidades em Joomla! Project

124 resultados
Análise Vexday

O Joomla! Project acumula 102 CVEs catalogadas, com uma taxa de exploração ativa 2,2 vezes acima da média geral do catálogo CISA KEV — sinal de que vulnerabilidades nessa plataforma tendem a ser efetivamente aproveitadas por atores maliciosos. O caso mais crítico em exploração ativa é CVE-2023-23752, com EPSS de 0,9983, indicando probabilidade extremamente elevada de exploração iminente ou em curso, e que deve ser tratada com prioridade máxima em qualquer ambiente Joomla! exposto. A falha mais comum é do tipo CWE-79 (Cross-Site Scripting), o que sugere fragilidades recorrentes na sanitização de entradas e saídas, especialmente relevante em um CMS com ampla superfície de extensões de terceiros. O volume de 26 CVEs surgidas nos últimos 90 dias reforça a necessidade de ciclos contínuos de atualização e monitoramento, sem depender apenas de janelas de manutenção periódicas.

CVE-2024-21731MEDIUM[20240703] - Core - XSS in StringHelper::truncate methodEPSS 0.4%CVE-2024-21729MEDIUM[20240701] - Core - XSS in accessible media selection fieldEPSS 0.4%CVE-2024-27185CRITICAL[20240802] - Core - Cache Poisoning in PaginationEPSS 0.4%CVE-2024-21730MEDIUM[20240702] - Core - Self-XSS in fancyselect list field layoutEPSS 0.4%CVE-2026-48948MEDIUMJoomla! Core - [20260702] - Incorrect Access Control in com_contact vcf downloadEPSS 0.4%CVE-2026-48957MEDIUMJoomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpointsEPSS 0.4%CVE-2024-40748HIGH[20250102] - Core - XSS vector in the id attribute of menu listsEPSS 0.4%CVE-2023-23754MEDIUM[20230501] - Core - Open Redirect and XSS within the mfa selectEPSS 0.4%CVE-2026-23899HIGHJoomla! Core - [20260306] - Improper access check in webservice endpointsEPSS 0.4%CVE-2020-35615[20201106] - Core - CSRF in com_privacy emailexport featureEPSS 0.4%CVE-2025-25227HIGH[20250402] - Joomla Core - MFA Authentication BypassEPSS 0.4%CVE-2022-27913[20221002] - Core - RXSS through reflection of user input in headingsEPSS 0.4%CVE-2024-40749HIGH[20250103] - Core - Read ACL violation in multiple core viewsEPSS 0.4%CVE-2026-73373HIGHJoomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.4%CVE-2024-27187HIGH[20240804] - Core - Improper ACL for backend profile viewEPSS 0.4%CVE-2026-35223HIGHJoomla! Core - [20260508] - Improper access check in com_config webservice endpointsEPSS 0.3%CVE-2026-48955MEDIUMJoomla! Core - [20260709] - Incorrect Access Control in com_workflowEPSS 0.3%CVE-2026-21630MEDIUMJoomla! Core - [20260302] - SQL injection in com_content articles webservice endpointEPSS 0.3%CVE-2026-48947MEDIUMJoomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpointsEPSS 0.3%CVE-2026-35221MEDIUMJoomla! Core - [20260506] - Authenticated blind SQLi in com_finderEPSS 0.3%