Joomla! Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Joomla! products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

1

Beyond CISA KEV

3

Sensor Observed

0

Virtual Patch Available

0

Joomla! KEVs Added by Year

Loading...

4 Joomla! KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2015-8562

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP...

High Not in CISA 16 Dec 2015
CVE-2013-5576

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote...

High Not in CISA 09 Oct 2013
CVE-2011-5148

Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote...

High Not in CISA 31 Aug 2012
CVE-2023-23752

[20230201] - Core - Improper access check in webservice endpoints

Confirmed In CISA 08 Jan 2024

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 2
  • CWE-284 — Improper Access Control 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology