Joomla! Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Joomla! products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
1
Beyond CISA KEV
3
Sensor Observed
0
Virtual Patch Available
0
Joomla! KEVs Added by Year
4 Joomla! KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2015-8562
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP... |
Joomla! | High | Not in CISA | 16 Dec 2015 |
|
CVE-2013-5576
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote... |
Joomla! | High | Not in CISA | 09 Oct 2013 |
|
CVE-2011-5148
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote... |
Simple File Upload | High | Not in CISA | 31 Aug 2012 |
|
CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints |
Joomla! CMS | Confirmed | In CISA | 08 Jan 2024 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 2
- CWE-284 — Improper Access Control 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology