PatchSiren

Joomla CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Joomla CVE published 2026-08-18

CVE-2026-73371

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T16:18:17.040Z and has not been modified since then. The NVD entry is currently Analyzed. This improper ACL checks vulnerability in Joomla Core affects versions 4.0.0-5.4.7 and 6.0.0-6.1.2, allowing unauthorized users to perform copy batch operations on uneditable items. Joomla site administrators [truncated]

MEDIUM Joomla CVE published 2026-08-18

CVE-2026-72532

The Joomla! Core has an Improper ACL checks vulnerability in category webservice endpoints, affecting versions 4.0.0-5.4.7 and 6.0.0-6.1.2. This allows unauthorized users to create categories via webservices endpoints. Affected deployments should prioritize updates and verify ACL checks. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. The CVE record was published on 2026-08-18T16:18:16 [truncated]

HIGH Joomla CVE published 2026-08-12

CVE-2026-73327

The com_joomlaupdate extension in Joomla 6.1.1 contains a path traversal vulnerability that allows a Super User to extract a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames, potentially leading to persistent remote code execution via planted PHP files. This vulnerability can be exploited by supplying malicious ZIP entry names with parent-directory segments [truncated]

HIGH Joomla CVE published 2026-06-19

CVE-2019-25757

CVE-2019-25757 is an SQL injection vulnerability in Joomla vWishlist 1.0.1. Authenticated attackers can inject malicious SQL code through the vproductid and userid parameters. This allows them to execute arbitrary SQL queries and extract sensitive database information, including version and database names. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Defenders should asses [truncated]

HIGH Joomla! CVE published 2026-06-19

CVE-2017-20269

CVE-2017-20269 is a high-severity SQL injection vulnerability in Joomla! Component KissGallery 1.0.0. Unaffected attackers can inject malicious SQL commands via the kissgallery endpoint, allowing for arbitrary database queries and sensitive information extraction. Defenders should prioritize patching or mitigating this vulnerability to limit exposure. The CVE was published on 2026-06-19T17:16:14.940Z.

HIGH Joomla! CVE published 2026-06-19

CVE-2017-20258

CVE-2017-20258 is a HIGH-severity SQL injection vulnerability in Joomla! Component RPC Responsive Portfolio 1.6.1. Unaffected attackers inject malicious SQL code via the id parameter in GET requests to index.php with option=com_pofos&view=pofo&id=[SQL]. This allows execution of arbitrary SQL queries, potentially extracting sensitive database information. Defenders should prioritize patching or mitigating [truncated]

Known exploited Joomla! CVE published 2024-01-08

CVE-2023-23752

CVE-2023-23752 is a Joomla! improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-01-08. The supplied corpus ties the issue to Joomla webservice endpoints and instructs defenders to apply vendor mitigations or stop using the product if mitigations are unavailable. Because the source corpus does not include affected versions, CVSS details, or exploit m [truncated]

CRITICAL Joomla CVE published 2017-01-23

CVE-2016-9081

CVE-2016-9081 is a critical Joomla account-modification vulnerability affecting Joomla 3.4.4 through 3.6.3. According to the NVD description, attackers may be able to reset usernames, passwords, and user group assignments, and possibly make other account changes through unspecified vectors. Because the issue can directly affect authentication and authorization data, it should be treated as urgent for any [truncated]