50 vulnerabilities · 41 with an official CVE

Joomla! 3 Security Vulnerabilities: The Complete CVE List

Joomla! 3 reached official end-of-life on 17 August 2023, and no more security updates come from the Joomla! Project. Since then, 50 vulnerabilities affecting the Joomla! 3 core have been identified and independently verified: 41 tied to an official CVE identifier, 9 additional hardening findings without a CVE. This page lists every one of them individually: CVE ID, vulnerability class, affected file, and how confident the finding is, so it's easy to search, cite, and check against your own site.

Last updated: 23.08.2026 · ← Back to the security patch

Vulnerabilities by class

Fixes by vulnerability class
ClassCount
XSS / Cross-Site-Scripting24
Access control / authentication9
Other hardening4
SQL injection2
Cache poisoning2
Timing attacks2
File upload / RCE2
Open redirect2
Path traversal / LFI1
PHP object injection1
Information disclosure1

Every vulnerability, individually

Every fix in the current package
IDTypeCVEClassFileConfidence
JP3-0001SecurityCVE-2025-54476XSS filter bypassInputFilter.phpHigh
JP3-0002SecurityCVE-2025-63083Stored XSStoc.phpHigh
JP3-0003SecurityCVE-2026-21629Missing authentication checkajax.phpHigh
JP3-0004SecurityCVE-2026-48954Stored XSS (attribute-breakout)languageoverridequotes.php +2 moreHigh
JP3-0005SecurityCVE-2026-48950Reflected XSSdefault.phpMedium
JP3-0006SecurityCVE-2026-48953XSS via public layout APIimage.phpMedium
JP3-0007SecurityCVE-2026-48952XSS via untrusted update feed datadefault.phpMedium
JP3-0008SecurityCVE-2026-25901Stored XSSedit.phpMedium
JP3-0009SecurityCVE-2026-30894Stored XSSpreview.phpHigh
JP3-0010SecurityCVE-2026-25900XSS via untrusted RSS feeddefault.php +1 moreHigh
JP3-0011SecurityCVE-2026-30895Stored XSSreadmore.php +1 moreMedium
JP3-0012SecurityCVE-2026-40383Path traversal to local file inclusionHtmlView.phpHigh
JP3-0013SecurityCVE-2026-35222SQL injectiontags.php +1 moreHigh
JP3-0014SecurityCVE-2026-48902Sensitive token sent over cleartext HTTPreset.php +1 moreHigh
JP3-0015SecurityCVE-2026-48901Cache poisoning / incorrect filter reuseInputFilter.phpHigh
JP3-0016SecurityCVE-2026-48948Broken access controlview.vcf.phpHigh
JP3-0017SecurityCVE-2025-63082XSS via data: URIInputFilter.phpHigh
JP3-0018SecurityCVE-2024-40747XSS via module style/attribute parametersModuleHelper.phpHigh
JP3-0019SecurityCVE-2025-25226SQL injection via identifier quoting bypassdriver.phpHigh
JP3-0020SecurityCVE-2026-21631Stored XSSedit.phpHigh
JP3-0021SecurityMissing authorization checkupdate.phpHigh
JP3-0022SecurityTiming side-channeltotp.phpHigh
JP3-0023SecurityMissing request/response authenticationyubikey.php +3 moreHigh
JP3-0024SecurityPHP object injection (defense-in-depth)restore.phpMedium
JP3-0025SecurityXSS via untrusted external feeddefault.phpHigh
JP3-0026SecurityTiming side-channel (limited real-world impact)reset.phpMedium
JP3-0027SecurityCode hygiene (eval removal) -- not found to be exploitableHtmlDocument.phpMedium
JP3-0028SecurityRemote code execution via file upload bypassMediaHelper.phpHigh
JP3-0029SecurityContent-type sniffing bypass (upload XSS)MediaHelper.phpHigh
JP3-0030SecurityCVE-2023-40626Information disclosure (env var / PHP constant exposure)LanguageHelper.php +28 moreHigh
JP3-0031SecurityCVE-2024-21723Open redirectframework.phpHigh
JP3-0032SecurityCVE-2024-27184Improper URL validation (open redirect / SSRF-adjacent)Uri.phpHigh
JP3-0033SecurityCVE-2024-21724XSS via unvalidated media-field valuebanner.xml +28 moreHigh
JP3-0034SecurityCVE-2024-26279XSS via malicious wrapper URL (javascript:/data: schemes)default.xml +1 moreHigh
JP3-0035SecurityCVE-2024-21726XSS filter gap in the URL form-validation ruleUrlRule.php +1 moreHigh
JP3-0036SecurityCVE-2024-21731XSS via entity-encoded tag surviving strip_tags then getting decoded livestring.phpHigh
JP3-0037SecurityCVE-2024-40743XSS via case-mixed or nested tag surviving a single-pass, case-sensitive strip regexOutputFilter.phpHigh
JP3-0038SecurityCVE-2024-27185Cache poisoning via arbitrary parameter injection into cached pagination linksPagination.phpHigh
JP3-0039SecurityCVE-2024-21722Insufficient session expiration after MFA method changeuser.php +1 moreHigh
JP3-0040SecurityCVE-2024-21725XSS via punycode-decoded email/URL containing HTML-special charactersdefault.php +7 moreMedium
JP3-0041SecurityCVE-2024-26278Stored XSS via unsanitized custom-field default valuefield.xmlHigh
JP3-0042SecurityCVE-2024-27187Improper access control (self-service privilege/identity tampering)user.phpMedium
JP3-0043SecurityCVE-2026-48898Missing authorization check (defense-in-depth; does not close a currently-reachable 3.x gap)user.phpMedium
JP3-0044SecurityCVE-2026-73371Improper access control (batch-copy items the user cannot edit)AdminModel.php +4 moreHigh
JP3-0045SecurityCVE-2026-48956Missing authorization check (defense-in-depth for a non-standard entry point)controller.phpMedium
JP3-0046SecurityCVE-2026-71572HTTP header injection via unsanitized filenameview.raw.php +1 moreHigh
JP3-0047SecurityCVE-2026-73373Remote code execution via file upload bypass (SSI-executable extension)template.phpHigh
JP3-0048SecurityCVE-2026-21632Stored XSS via unescaped article titleblog_links.php +6 moreHigh
JP3-0049SecurityCVE-2024-40748XSS via unescaped HTML id attributedefault.phpHigh
JP3-0050SecurityCVE-2024-40749Access control bypass via case-insensitive class resolution vs. case-sensitive ACL checkcontroller.php +1 moreHigh
JP3-0051PHP 8PHP 8.1 compatibility (Serializable interface deprecation notice, not a vulnerability)Input.php +1 moreHigh
JP3-0052PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)Feed.phpHigh
JP3-0053PHP 8PHP 8.4 compatibility (implicit-nullable-parameter deprecation, not a vulnerability)BaseApplication.php +6 moreHigh
JP3-0054PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)iterator.phpHigh
JP3-0055PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)iterator.phpHigh
JP3-0056PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)DataSet.phpHigh
JP3-0057PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)Input.phpHigh

CVE identifiers link to their official record in the National Vulnerability Database (NVD).

Want these fixed on your site?

This is the same dataset behind our Joomla! 3 Security Patch: a one-click Scan & Apply tool that fixes all 50 of these on your own installation.

Get the Security Patch · $19.90

Frequently asked questions

Why do some entries have no CVE number?

Not every vulnerability gets a formal CVE identifier assigned. These entries are still independently verified findings, listed with a dash where no CVE exists, exactly as the table shows.

Does this list only cover the Joomla! core, or extensions too?

Core only. This is specifically the Joomla! 3 core, the same code every Joomla! 3 site runs regardless of which extensions are installed. Extension vulnerabilities are a separate, much larger and site-specific list.

Will this list grow over time?

It can. Joomla! 3 no longer gets official fixes, but new vulnerabilities are still occasionally identified in code it shares with newer Joomla! versions. This page is updated when that happens.

How was each entry verified?

Each is checked against the actual Joomla! 3 core source, not just copied from a public advisory description, which is why some entries carry a confidence rating of Medium rather than High.