• About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
    • User Guide
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
    • What is Joomla Academy?
    • What is Google Summer of Code (GSoc)
    • Joomla License FAQs
    • Developer Network
    • Developer Manual
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework
Joomla! Developer Network™
Download
Launch
  • Home
  • News
  • Project Roadmap
  • CMS
  • Framework
  • Tracker
  • About
  • Security

Security Announcements

This feed provides announcements of resolved security issues in Joomla! software releases.

For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.

To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.

You can subscribe to notifications from this feed through a RSS reader.

[20230102] - Core - Missing ACL checks for com_actionlogs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-4.2.6
  • Exploit type: Incorrect Access Control
  • Reported Date: 2023-01-01
  • Fixed Date: 2023-01-31
  • CVE Number: CVE-2023-23751

Description

A missing ACL check allows non super-admin users to access com_actionlogs.

Affected Installs

Joomla! CMS versions 4.0.0-4.2.6

Solution

Upgrade to version 4.2.7

Contact

The JSST at the Joomla! Security Centre.

Reported By: Faizan Wani

[20221002] - Core - RXSS through reflection of user input in headings

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-4.2.3
  • Exploit type: Reflexted XSS
  • Reported Date: 2022-10-07
  • Fixed Date: 2022-10-25
  • CVE Number: CVE-2022-27913

Description

Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 4.0.0-4.2.3

Solution

Upgrade to version 4.2.4

Contact

The JSST at the Joomla! Security Centre.

Reported By: Ajith Menon

[20221001] - Core - Disclosure of critical information in debug mode

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Critical
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-4.2.3
  • Exploit type: Information Disclosure
  • Reported Date: 2022-10-13
  • Fixed Date: 2022-10-25
  • CVE Number: CVE-2022-27912

Description

Joomla 4 sites with publicly enabled debug mode exposed data of previous requests.

Affected Installs

Joomla! CMS versions 4.0.0-4.2.3

Solution

Upgrade to version 4.2.4

Contact

The JSST at the Joomla! Security Centre.

Reported By: Peter Martin

[20220801] - Core - Multiple Full Path Disclosures because of missing '_JEXEC or die check'

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.2.0
  • Exploit type: Path Disclosure
  • Reported Date: 2022-08-27
  • Fixed Date: 2022-08-30
  • CVE Number: CVE-2022-27911

Description

Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes done in 4.2.0. According to PROD2020/023 and in coordination with the JSST this has been patched in the public tracker vis #38615

Affected Installs

Joomla! CMS versions 4.2.0

Solution

Upgrade to version 4.2.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: SharkyKZ

[20220301] - Core - Zip Slip within the Tar extractor

  • Project: Joomla! / Joomla! Framework
  • SubProject: CMS / archive
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 3.0.0 - 3.10.6 & 4.0.0 - 4.1.0
  • Exploit type: Path Traversal
  • Reported Date: 2022-02-20
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23793

Description

Extracting an specifilcy crafted tar package could write files outside of the intended path.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.10.6 & 4.0.0 - 4.1.0

Solution

Upgrade to version 3.10.7 or 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Egidio Romano

[20220302] - Core - Path Disclosure within filesystem error messages

  • Project: Joomla! / Joomla! Framework
  • SubProject: CMS / filesystem
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 3.0.0 - 3.10.6 & 4.0.0 - 4.1.0
  • Exploit type: Path Disclosure
  • Reported Date: 2021-02-17
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23794

Description

Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.10.6 & 4.0.0 - 4.1.0

Solution

Upgrade to version 3.10.7 or 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: DangKhai from Viettel Cyber Security

[20220303] - Core - User row are not bound to a authentication mechanism

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Probability: Low
  • Versions: 2.5.0 - 3.10.6 & 4.0.0 - 4.1.0
  • Exploit type: Incorrect Access Control
  • Reported Date: 2020-09-23
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23795

Description

A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.10.6 & 4.0.0 - 4.1.0

Solution

Upgrade to version 3.10.7 or 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Phil Taylor

[20220304] - Core - Missing input validation within com_fields class inputs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 3.7.0 - 3.10.6
  • Exploit type: XSS
  • Reported Date: 2021-05-06
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23796

Description

Lack of input validation could allow an XSS attack using com_fields

Affected Installs

Joomla! CMS versions 3.7.0 - 3.10.6

Solution

Upgrade to version 3.10.7

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoàng Nguyễn

[20220305] - Core - Inadequate filtering on the selected Ids

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Probability: Low
  • Versions: 3.0.0 - 3.10.6 & 4.0.0 - 4.1.0
  • Exploit type: SQL Injection
  • Reported Date: 2021-03-04
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23797

Description

Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.10.6 & 4.0.0 - 4.1.0

Solution

Upgrade to version 3.10.7 & 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoàng Nguyễn

[20220306] - Core - Inadequate validation of internal URLs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 2.5.0 - 3.10.6 & 4.0.0 - 4.1.0
  • Exploit type: Open redirect
  • Reported Date: 2021-03-23
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23798

Description

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.10.6 & 4.0.0 - 4.1.0

Solution

Upgrade to version 3.10.7 & 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Loïc LE MÉTAYER

[20220307] - Core - Variable Tampering on JInput $_REQUEST data

  • Project: Joomla! / Joomla! Framework
  • SubProject: CMS / input
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0 - 4.1.0
  • Exploit type: Variable Tampering
  • Reported Date: 2021-11-05
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23799

Description

Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

Affected Installs

Joomla! CMS versions 4.0.0 - 4.1.0

Solution

Upgrade to version 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Nicholas K. Dionysopoulos, Phil Taylor

[20220308] - Core - Inadequate content filtering within the filter code

  • Project: Joomla! / Joomla! Framework
  • SubProject: CMS / filter
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0 - 4.1.0
  • Exploit type: XSS
  • Reported Date: 2022-01-19
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23800

Description

Inadequate content filtering leads to XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 4.0.0 - 4.1.0

Solution

Upgrade to version 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Sebastian Morris, pwnCTRL

[20220309] - Core - XSS attack vector through SVG

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0 - 4.1.0
  • Exploit type: XSS
  • Reported Date: 2021-08-25
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23801

Description

Possible XSS attack vector through SVG embedding in com_media.

Affected Installs

Joomla! CMS versions 4.0.0 - 4.1.0

Solution

Upgrade to version 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Julia Polner, Simon Stockhause

[20210801] - Core - Insufficient access control for com_media deletion endpoint

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: High
  • Versions: 4.0.0
  • Exploit type: Incorrect Access Control
  • Reported Date: 2021-08-20
  • Fixed Date: 2021-08-24
  • CVE Number: CVE-2021-26040

Description

The media manager does not correctly check the user's permissions before executing a file deletion command.

Affected Installs

Joomla! CMS versions 4.0.0

Solution

Upgrade to version 4.0.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Maverick

[20210705] - Core - XSS in com_media imagelist

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 3.0.0 - 3.9.27
  • Exploit type: XSS
  • Reported Date: 2021-06-22
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26039

Description

Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hagai Wechsler / WhiteSourceSoftware

[20210704] - Core - Privilege escalation through com_installer

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: Incorrect Access Control
  • Reported Date: 2021-06-06
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26038

Description

Install action in com_installer lack the required hardcoded ACL checks for superusers, leading to various potential attack vectors. A default system is not affected cause by default com_installer is limited to super users already.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Nicholas Dionysopoulos

[20210703] - Core - Lack of enforced session termination

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: Incorrect Session Handling
  • Reported Date: 2019-02-08
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26037

Description

Various CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Carsten Schmitz, Atik Islam, Dennis Hermatski, Muhammad Hussain, th3lawbreaker, Hoang Kien

[20210702] - Core - DoS through usergroup table manipulation

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: DoS
  • Reported Date: 2021-06-08
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26036

Description

Missing validation of input could lead to a broken usergroups table.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoang Kien from VSEC

[20210701] - Core - XSS in JForm Rules field

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.27
  • Exploit type: XSS
  • Reported Date: 2021-05-29
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26035

Description

Inadequate escaping in the Rules field of the JForm API leads to a XSS vulnerability.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoang Nguyen

[20210503] - Core - CSRF in data download endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.26
  • Exploit type: CSRF
  • Reported Date: 2021-05-07
  • Fixed Date: 2021-05-25
  • CVE Number: CVE-2021-26034

Description

A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.26

Solution

Upgrade to version 3.9.27

Contact

The JSST at the Joomla! Security Centre.

Reported By: Phil Taylor

[20210502] - Core - CSRF in AJAX reordering endpoint

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.26
  • Exploit type: CSRF
  • Reported Date: 2021-05-07
  • Fixed Date: 2021-05-25
  • CVE Number: CVE-2021-26033

Description

A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.26

Solution

Upgrade to version 3.9.27

Contact

The JSST at the Joomla! Security Centre.

Reported By: Phil Taylor

[20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUpload

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.26
  • Exploit type: XSS
  • Reported Date: 2021-03-05
  • Fixed Date: 2021-05-25
  • CVE Number: CVE-2021-26032

Description

HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.26

Solution

Upgrade to version 3.9.27

Contact

The JSST at the Joomla! Security Centre.

Reported By: Adrian Tiron, Fortbridge

[20210402] - Core - Inadequate filters on module layout settings

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.25
  • Exploit type: LFI
  • Reported Date: 2021-01-03
  • Fixed Date: 2021-04-13
  • CVE Number: CVE-2021-26031

Description

Inadequate filters on module layout settings could lead to an LFI.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.25

Solution

Upgrade to version 3.9.26

Contact

The JSST at the Joomla! Security Centre.

Reported By: Lee Thao from Viettel Cyber Security

[20210401] - Core - Escape xss in logo parameter error pages

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.25
  • Exploit type: XSS
  • Reported Date: 2021-03-09
  • Fixed Date: 2021-04-13
  • CVE Number: CVE-2021-26030

Description

Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error pages.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.25

Solution

Upgrade to version 3.9.26

Contact

The JSST at the Joomla! Security Centre.

Reported By: HOANG NGUYEN

[20210305] - Core - Input validation within the template manager

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.2.0 - 3.9.24
  • Exploit type: Improper Input Validation
  • Reported Date: 2020-05-07
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23131

Description

Missing input validation within the template manager.

Affected Installs

Joomla! CMS versions 3.2.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Bui Duc Anh Khoa from Zalo Security Team

Page 3 of 13

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  1. You are here:  
  2. Home
  3. Security Announcements

Joomla! CMS

  • Current Release Joomla! CMS 6 6.x
  • View known Issues
  • Development Status
  • Download Nightly builds

Joomla! Framework

  • Current Release Joomla! Framework Logo 4.x
  • Development Status

Resources

  • Development Strategy
  • Product Strategy
  • Planned Features
  • Security Announcements
  • Report Security Issues
  • Generative AI policy
  • Usage Statistics
  • Statistics API Documentation
  • Joomla! API Documentation
  • Coding Standards Manual
  • JoomlaCode Archive

Mailing Lists

  • Developer Network Newsletter
  • General Extensions Mailing
  • CMS Mailing
  • Framework Mailing
  • Documentation Mailing

  • Joomla! on Facebook
  • Joomla! on X
  • Joomla! on Bluesky
  • Joomla! on Threads
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • User Guide
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in
 A Digital Public Good.

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.