Exposición de Joomla

CMS
986
score de exposición
94.953
sitios usan
4
en explotación
58
críticos
Análisis Vexday

O Joomla acumula 223 CVEs catalogadas, com 24 classificadas como críticas e 49 surgidas apenas nos últimos 90 dias, indicando ritmo contínuo de descoberta de vulnerabilidades. A taxa de exploração ativa — 0,9% das CVEs presentes no catálogo CISA KEV — está 2× acima da média geral do catálogo, o que sugere que adversários demonstram interesse concreto em abusar de falhas nessa plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), historicamente difícil de erradicar em sistemas baseados em extensões de terceiros. A CVE mais perigosa em exploração ativa, CVE-2023-23752, carrega um score EPSS de 0,9983 — praticamente a probabilidade máxima de exploração —, tornando sua correção imediata uma prioridade inegociável para qualquer instância exposta.

CVEs

332 resultados
CVE-2023-23753CRITICALExtension - vi-solutions - Visforms Base Package for Joomla 3EPSS 0.8%CVE-2021-23130[20210304] - Core - XSS within the feed parser libraryEPSS 0.8%CVE-2021-23129[20210303] - Core - XSS within alert messages showed to usersEPSS 0.8%CVE-2025-22204CRITICALExtension - regularlabs.com - Remote code execution vulnerability in the Sourcerer extensions < 12.0.0 for JoomlaEPSS 0.8%CVE-2011-4912Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.EPSS 0.8%CVE-2021-23125[20210103] - Core - XSS in com_tags image parametersEPSS 0.8%CVE-2021-26039[20210705] - Core - XSS in com_media imagelistEPSS 0.7%CVE-2021-26035[20210701] - Core - XSS in JForm Rules fieldEPSS 0.7%CVE-2023-40630CRITICALExtension - joomcode.com - Unauthenticated LFI/SSRF in JCDashboards component for Joomla 1.0.0-1.1.30EPSS 0.7%CVE-2022-23800[20220308] - Core - Inadequate content filtering within the filter codeEPSS 0.7%CVE-2016-15016MEDIUMmrtnmtth joomla_mod_einsatz_stats helper.php getStatsByType sql injectionEPSS 0.7%CVE-2023-28732MEDIUMMissing access control affecting the AcyMailing plugin for JoomlaEPSS 0.6%CVE-2025-22208MEDIUMExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.3 for JoomlaEPSS 0.6%CVE-2022-23798[20220306] - Core - Inadequate validation of internal URLsEPSS 0.6%CVE-2022-23801[20220309] - Core - XSS attack vector through SVGEPSS 0.6%CVE-2022-23796[20220304] - Core - Missing input validation within com_fields class inputsEPSS 0.6%CVE-2023-23755HIGH[20230502] - Core - Bruteforce prevention within the mfa screenEPSS 0.6%CVE-2026-65883CRITICALJoomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0EPSS 0.6%CVE-2026-34424CRITICALSmart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access ToolkitEPSS 0.6%CVE-2024-32788MEDIUMWordPress FG Joomla to Wordpress plugin <= 4.20.2 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.5%