• About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
    • User Guide
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
    • What is Joomla Academy?
    • What is Google Summer of Code (GSoc)
    • Joomla License FAQs
    • Developer Network
    • Developer Manual
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework
Joomla! Developer Network™
Download
Launch
  • Home
  • News
  • Project Roadmap
  • CMS
  • Framework
  • Tracker
  • About
  • Security

Security Announcements

This feed provides announcements of resolved security issues in Joomla! software releases.

For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.

To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.

You can subscribe to notifications from this feed through a RSS reader.

[20220307] - Core - Variable Tampering on JInput $_REQUEST data

  • Project: Joomla! / Joomla! Framework
  • SubProject: CMS / input
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0 - 4.1.0
  • Exploit type: Variable Tampering
  • Reported Date: 2021-11-05
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23799

Description

Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

Affected Installs

Joomla! CMS versions 4.0.0 - 4.1.0

Solution

Upgrade to version 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Nicholas K. Dionysopoulos, Phil Taylor

[20220308] - Core - Inadequate content filtering within the filter code

  • Project: Joomla! / Joomla! Framework
  • SubProject: CMS / filter
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0 - 4.1.0
  • Exploit type: XSS
  • Reported Date: 2022-01-19
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23800

Description

Inadequate content filtering leads to XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 4.0.0 - 4.1.0

Solution

Upgrade to version 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Sebastian Morris, pwnCTRL

[20220309] - Core - XSS attack vector through SVG

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0 - 4.1.0
  • Exploit type: XSS
  • Reported Date: 2021-08-25
  • Fixed Date: 2022-03-29
  • CVE Number: CVE-2022-23801

Description

Possible XSS attack vector through SVG embedding in com_media.

Affected Installs

Joomla! CMS versions 4.0.0 - 4.1.0

Solution

Upgrade to version 4.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Julia Polner, Simon Stockhause

[20210801] - Core - Insufficient access control for com_media deletion endpoint

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: High
  • Versions: 4.0.0
  • Exploit type: Incorrect Access Control
  • Reported Date: 2021-08-20
  • Fixed Date: 2021-08-24
  • CVE Number: CVE-2021-26040

Description

The media manager does not correctly check the user's permissions before executing a file deletion command.

Affected Installs

Joomla! CMS versions 4.0.0

Solution

Upgrade to version 4.0.1

Contact

The JSST at the Joomla! Security Centre.

Reported By: Maverick

[20210705] - Core - XSS in com_media imagelist

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 3.0.0 - 3.9.27
  • Exploit type: XSS
  • Reported Date: 2021-06-22
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26039

Description

Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hagai Wechsler / WhiteSourceSoftware

[20210704] - Core - Privilege escalation through com_installer

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: Incorrect Access Control
  • Reported Date: 2021-06-06
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26038

Description

Install action in com_installer lack the required hardcoded ACL checks for superusers, leading to various potential attack vectors. A default system is not affected cause by default com_installer is limited to super users already.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Nicholas Dionysopoulos

[20210703] - Core - Lack of enforced session termination

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: Incorrect Session Handling
  • Reported Date: 2019-02-08
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26037

Description

Various CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Carsten Schmitz, Atik Islam, Dennis Hermatski, Muhammad Hussain, th3lawbreaker, Hoang Kien

[20210702] - Core - DoS through usergroup table manipulation

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: DoS
  • Reported Date: 2021-06-08
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26036

Description

Missing validation of input could lead to a broken usergroups table.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoang Kien from VSEC

[20210701] - Core - XSS in JForm Rules field

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.27
  • Exploit type: XSS
  • Reported Date: 2021-05-29
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26035

Description

Inadequate escaping in the Rules field of the JForm API leads to a XSS vulnerability.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.27

Solution

Upgrade to version 3.9.28

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoang Nguyen

[20210503] - Core - CSRF in data download endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.26
  • Exploit type: CSRF
  • Reported Date: 2021-05-07
  • Fixed Date: 2021-05-25
  • CVE Number: CVE-2021-26034

Description

A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.26

Solution

Upgrade to version 3.9.27

Contact

The JSST at the Joomla! Security Centre.

Reported By: Phil Taylor

[20210502] - Core - CSRF in AJAX reordering endpoint

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.26
  • Exploit type: CSRF
  • Reported Date: 2021-05-07
  • Fixed Date: 2021-05-25
  • CVE Number: CVE-2021-26033

Description

A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.26

Solution

Upgrade to version 3.9.27

Contact

The JSST at the Joomla! Security Centre.

Reported By: Phil Taylor

[20210501] - Core - Adding HTML to the executable block list of MediaHelper::canUpload

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.26
  • Exploit type: XSS
  • Reported Date: 2021-03-05
  • Fixed Date: 2021-05-25
  • CVE Number: CVE-2021-26032

Description

HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.26

Solution

Upgrade to version 3.9.27

Contact

The JSST at the Joomla! Security Centre.

Reported By: Adrian Tiron, Fortbridge

[20210402] - Core - Inadequate filters on module layout settings

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.25
  • Exploit type: LFI
  • Reported Date: 2021-01-03
  • Fixed Date: 2021-04-13
  • CVE Number: CVE-2021-26031

Description

Inadequate filters on module layout settings could lead to an LFI.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.25

Solution

Upgrade to version 3.9.26

Contact

The JSST at the Joomla! Security Centre.

Reported By: Lee Thao from Viettel Cyber Security

[20210401] - Core - Escape xss in logo parameter error pages

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.0.0 - 3.9.25
  • Exploit type: XSS
  • Reported Date: 2021-03-09
  • Fixed Date: 2021-04-13
  • CVE Number: CVE-2021-26030

Description

Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error pages.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.25

Solution

Upgrade to version 3.9.26

Contact

The JSST at the Joomla! Security Centre.

Reported By: HOANG NGUYEN

[20210305] - Core - Input validation within the template manager

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.2.0 - 3.9.24
  • Exploit type: Improper Input Validation
  • Reported Date: 2020-05-07
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23131

Description

Missing input validation within the template manager.

Affected Installs

Joomla! CMS versions 3.2.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Bui Duc Anh Khoa from Zalo Security Team

[20210301] - Core - Insecure randomness within 2FA secret generation

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.2.0 - 3.9.24
  • Exploit type: Insecure Randomness
  • Reported Date: 2021-01-12
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23126, CVE-2021-23127

Description

Usage of the insecure rand() function within the process of generating the 2FA secret.
Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.

Additional details as well as a more contexts for exising sites can be found in the docs: https://docs.joomla.org/J3.x:Changes_to_the_2FA_token_generation_recommendations_for_existing_sites

This issue has been coordinated with Akeeba Ltd as contributor of the original FOF codebase to the core.

Affected Installs

Joomla! CMS versions 3.2.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hanno Böck

[20210302] - Core - Potential Insecure FOFEncryptRandval

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.2.0 - 3.9.24
  • Exploit type: Insecure Randomness
  • Reported Date: 2021-01-13
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23128

Description

The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to "random_bytes()" and its backport that is shipped within random_compat.

This issue has been coordinated with Akeeba Ltd as contributor of the original FOF codebase to the core.

Affected Installs

Joomla! CMS versions 3.2.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hanno Böck

[20210303] - Core - XSS within alert messages showed to users

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 2.5.0 - 3.9.24
  • Exploit type: XSS
  • Reported Date: 2020-05-07
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23129

Description

Missing filtering of messages showed to users that could lead to xss issues.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Bui Duc Anh Khoa from Zalo Security Team

[20210308] - Core - Path Traversal within joomla/archive zip class

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 3.0.0 - 3.9.24
  • Exploit type: Path Traversal
  • Reported Date: 2020-09-08
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-26028

Description

Extracting an specifilcy crafted zip package could write files outside of the intended path.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Šarūnas Paulauskas, Lee Jinheon

[20210304] - Core - XSS within the feed parser library

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 2.5.0 - 3.9.24
  • Exploit type: XSS
  • Reported Date: 2020-05-05
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23130

Description

Missing filtering of feed fields could lead to xss issues.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Bui Duc Anh Khoa from Zalo Security Team

[20210306] - Core - com_media allowed paths that are not intended for image uploads

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 3.0.0 - 3.9.24
  • Exploit type: Improper Input Validation
  • Reported Date: 2020-02-17
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-23132

Description

com_media allowed paths that are not intended for image uploads.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hoang Kien from VSEC

[20210307] - Core - ACL violation within com_content frontend editing

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 3.0.0 - 3.9.24
  • Exploit type: ACL violation
  • Reported Date: 2020-10-25
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-26027

Description

Incorrect ACL checks could allow unauthorized change of the category for an article.

Affected Installs

Joomla! CMS versions 3.0.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: Brian Teeman, George Wilson (JSST), David Jardin (JSST)

[20210309] - Core - Inadequate filtering of form contents could allow to overwrite the author field

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 1.6.0 - 3.9.24
  • Exploit type: ACL Violation
  • Reported Date: 2021-01-31
  • Fixed Date: 2021-03-02
  • CVE Number: CVE-2021-26029

Description

Inadequate filtering of form contents could allow to overwrite the author field. The affected core components are com_fields, com_categories, com_banners, com_contact, com_newsfeeds and com_tags. 

Affected Installs

Joomla! CMS versions 1.6.0 - 3.9.24

Solution

Upgrade to version 3.9.25

Contact

The JSST at the Joomla! Security Centre.

Reported By: DangKhai from Viettel Cyber Security

[20210103] - Core - XSS in com_tags image parameters

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions:3.1.0 - 3.9.23
  • Exploit type: XSS
  • Reported Date: 2020-09-01
  • Fixed Date: 2021-01-12
  • CVE Number: CVE-2021-23125

Description

Lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.

Affected Installs

Joomla! CMS versions 3.1.0 - 3.9.23

Solution

Upgrade to version 3.9.24

Contact

The JSST at the Joomla! Security Centre.

Reported By: Šarūnas Paulauskas

[20210102] - Core - XSS in mod_breadcrumbs aria-label attribute

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions:3.9.0 - 3.9.23
  • Exploit type: XSS
  • Reported Date: 2020-09-01
  • Fixed Date: 2021-01-12
  • CVE Number: CVE-2021-23124

Description

Lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

Affected Installs

Joomla! CMS versions 3.9.0 - 3.9.23

Solution

Upgrade to version 3.9.24

Contact

The JSST at the Joomla! Security Centre.

Reported By: Šarūnas Paulauskas

Page 4 of 14

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  1. You are here:  
  2. Home
  3. Security Announcements

Joomla! CMS

  • Current Release Joomla! CMS 6 6.x
  • View known Issues
  • Development Status
  • Download Nightly builds

Joomla! Framework

  • Current Release Joomla! Framework Logo 4.x
  • Development Status

Resources

  • Development Strategy
  • Product Strategy
  • Planned Features
  • Security Announcements
  • Report Security Issues
  • Generative AI policy
  • Usage Statistics
  • Statistics API Documentation
  • Joomla! API Documentation
  • Coding Standards Manual
  • JoomlaCode Archive

Mailing Lists

  • Developer Network Newsletter
  • General Extensions Mailing
  • CMS Mailing
  • Framework Mailing
  • Documentation Mailing

  • Joomla! on Facebook
  • Joomla! on X
  • Joomla! on Bluesky
  • Joomla! on Threads
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • User Guide
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in
 A Digital Public Good.

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.