SecAlerts
J

Joomla

Security Risk Profile

54
/100
medium

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 12, 2007 to present

1000
Total CVEs
588
Critical+High
4
Exploited
543
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
543
Critical/High
Risk Level
54/100
medium
⚠️ 4 Active Exploits🆕 1Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
54
High
534
Medium
405
Low
7

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
410
2
XSS
181
3
Path Traversal
133
4
Code Injection
46
5
Input Validation
34

Most Affected Products

1. Joomla Joomla\!2994
2. Joomla joomla304
3. RSGallery2 Com Rsgallery2118
4. Algisinfo Aicontactsafe59
5. Drupal User Karma module52

Recent Vulnerabilities

See more →
CVE-2026-88857
CVSS 9.4critical

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7

Sep 20, 2026🔧 No Patch
CVE-2026-84048
CVSS 6.3medium

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2

Sep 15, 2026🔧 No Patch
CVE-2026-81565
CVSS 6.9medium

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0

Sep 14, 2026🔧 No Patch
CVE-2026-77999
CVSS 8.7high

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6

Sep 3, 2026🔧 No Patch
CVE-2026-78071
CVSS 7.5high

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0

Aug 28, 2026🔧 No Patch
CVE-2026-78073
CVSS 5.3medium

Joomla Extension - j2commerce.com - Reflected XSS attribute in All Video Share 1.0.0-4.5.0

Aug 28, 2026🔧 No Patch
CVE-2026-77034
CVSS 6.9medium

Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1

Aug 27, 2026🔧 No Patch
CVE-2026-77035
CVSS 5.1medium

Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1

Aug 27, 2026🔧 No Patch
CVE-2026-77994
CVSS 9.3critical

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5

Aug 24, 2026🔧 No Patch
CVE-2026-76571
CVSS 9.3critical

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2

Aug 22, 2026🔧 No Patch

Monitor Joomla in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Joomla Security Vulnerabilities & Risk Score | 1000 CVEs | SecAlerts - SecAlerts