Joomla Vulnerabilities and Affected Products
Vulnerabilities associated with joomla\!.
Products
Clear product- joomla\!2 vulnerabilities
- Joomla! CMS1 vulnerability
- WP Meta SEO plugin for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-27187HIGH | [20240804] - Core - Improper ACL for backend profile viewImproper Access Controls allows backend users to overwrite their username when disallowed. CWE-284Aug 20, 2024 | CVSS7.5v3.1 | EPSS0.354% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-23752MEDIUM | [20230201] - Core - Improper access check in webservice endpointsAn issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | CVSS5.3v3.1 | EPSS99.8% | PoCs51 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |