50 vulnerabilities · 41 with an official CVE

Joomla! 3 Security Vulnerabilities: The Complete CVE List

Joomla! 3 reached official end-of-life on 17 August 2023, and no more security updates come from the Joomla! Project. Since then, 50 vulnerabilities affecting the Joomla! 3 core have been identified and independently verified: 41 tied to an official CVE identifier, 9 additional hardening findings without a CVE. This page lists every one of them individually: CVE ID, vulnerability class, affected file, and how confident the finding is, so it's easy to search, cite, and check against your own site.

Last updated: 23.08.2026 · ← Back to the security patch

Vulnerabilities by class

Fixes by vulnerability class
ClassCount
XSS / Cross-Site-Scripting24
Access control / authentication9
Other hardening4
SQL injection2
Cache poisoning2
Timing attacks2
File upload / RCE2
Open redirect2
Path traversal / LFI1
PHP object injection1
Information disclosure1

Every vulnerability, individually

Every fix in the current package
IDTypeCVEClassFileConfidence
JP3-0001SecurityCVE-2025-54476XSS filter bypassInputFilter.phpHigh
JP3-0002SecurityCVE-2025-63083Stored XSStoc.phpHigh
JP3-0003SecurityCVE-2026-21629Missing authentication checkajax.phpHigh
JP3-0004SecurityCVE-2026-48954Stored XSS (attribute-breakout)languageoverridequotes.php +2 moreHigh
JP3-0005SecurityCVE-2026-48950Reflected XSSdefault.phpMedium
JP3-0006SecurityCVE-2026-48953XSS via public layout APIimage.phpMedium
JP3-0007SecurityCVE-2026-48952XSS via untrusted update feed datadefault.phpMedium
JP3-0008SecurityCVE-2026-25901Stored XSSedit.phpMedium
JP3-0009SecurityCVE-2026-30894Stored XSSpreview.phpHigh
JP3-0010SecurityCVE-2026-25900XSS via untrusted RSS feeddefault.php +1 moreHigh
JP3-0011SecurityCVE-2026-30895Stored XSSreadmore.php +1 moreMedium
JP3-0012SecurityCVE-2026-40383Path traversal to local file inclusionHtmlView.phpHigh
JP3-0013SecurityCVE-2026-35222SQL injectiontags.php +1 moreHigh
JP3-0014SecurityCVE-2026-48902Sensitive token sent over cleartext HTTPreset.php +1 moreHigh
JP3-0015SecurityCVE-2026-48901Cache poisoning / incorrect filter reuseInputFilter.phpHigh
JP3-0016SecurityCVE-2026-48948Broken access controlview.vcf.phpHigh
JP3-0017SecurityCVE-2025-63082XSS via data: URIInputFilter.phpHigh
JP3-0018SecurityCVE-2024-40747XSS via module style/attribute parametersModuleHelper.phpHigh
JP3-0019SecurityCVE-2025-25226SQL injection via identifier quoting bypassdriver.phpHigh
JP3-0020SecurityCVE-2026-21631Stored XSSedit.phpHigh
JP3-0021SecurityMissing authorization checkupdate.phpHigh
JP3-0022SecurityTiming side-channeltotp.phpHigh
JP3-0023SecurityMissing request/response authenticationyubikey.php +3 moreHigh
JP3-0024SecurityPHP object injection (defense-in-depth)restore.phpMedium
JP3-0025SecurityXSS via untrusted external feeddefault.phpHigh
JP3-0026SecurityTiming side-channel (limited real-world impact)reset.phpMedium
JP3-0027SecurityCode hygiene (eval removal) -- not found to be exploitableHtmlDocument.phpMedium
JP3-0028SecurityRemote code execution via file upload bypassMediaHelper.phpHigh
JP3-0029SecurityContent-type sniffing bypass (upload XSS)MediaHelper.phpHigh
JP3-0030SecurityCVE-2023-40626Information disclosure (env var / PHP constant exposure)LanguageHelper.php +28 moreHigh
JP3-0031SecurityCVE-2024-21723Open redirectframework.phpHigh
JP3-0032SecurityCVE-2024-27184Improper URL validation (open redirect / SSRF-adjacent)Uri.phpHigh
JP3-0033SecurityCVE-2024-21724XSS via unvalidated media-field valuebanner.xml +28 moreHigh
JP3-0034SecurityCVE-2024-26279XSS via malicious wrapper URL (javascript:/data: schemes)default.xml +1 moreHigh
JP3-0035SecurityCVE-2024-21726XSS filter gap in the URL form-validation ruleUrlRule.php +1 moreHigh
JP3-0036SecurityCVE-2024-21731XSS via entity-encoded tag surviving strip_tags then getting decoded livestring.phpHigh
JP3-0037SecurityCVE-2024-40743XSS via case-mixed or nested tag surviving a single-pass, case-sensitive strip regexOutputFilter.phpHigh
JP3-0038SecurityCVE-2024-27185Cache poisoning via arbitrary parameter injection into cached pagination linksPagination.phpHigh
JP3-0039SecurityCVE-2024-21722Insufficient session expiration after MFA method changeuser.php +1 moreHigh
JP3-0040SecurityCVE-2024-21725XSS via punycode-decoded email/URL containing HTML-special charactersdefault.php +7 moreMedium
JP3-0041SecurityCVE-2024-26278Stored XSS via unsanitized custom-field default valuefield.xmlHigh
JP3-0042SecurityCVE-2024-27187Improper access control (self-service privilege/identity tampering)user.phpMedium
JP3-0043SecurityCVE-2026-48898Missing authorization check (defense-in-depth; does not close a currently-reachable 3.x gap)user.phpMedium
JP3-0044SecurityCVE-2026-73371Improper access control (batch-copy items the user cannot edit)AdminModel.php +4 moreHigh
JP3-0045SecurityCVE-2026-48956Missing authorization check (defense-in-depth for a non-standard entry point)controller.phpMedium
JP3-0046SecurityCVE-2026-71572HTTP header injection via unsanitized filenameview.raw.php +1 moreHigh
JP3-0047SecurityCVE-2026-73373Remote code execution via file upload bypass (SSI-executable extension)template.phpHigh
JP3-0048SecurityCVE-2026-21632Stored XSS via unescaped article titleblog_links.php +6 moreHigh
JP3-0049SecurityCVE-2024-40748XSS via unescaped HTML id attributedefault.phpHigh
JP3-0050SecurityCVE-2024-40749Access control bypass via case-insensitive class resolution vs. case-sensitive ACL checkcontroller.php +1 moreHigh
JP3-0051PHP 8PHP 8.1 compatibility (Serializable interface deprecation notice, not a vulnerability)Input.php +1 moreHigh
JP3-0052PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)Feed.phpHigh
JP3-0053PHP 8PHP 8.4 compatibility (implicit-nullable-parameter deprecation, not a vulnerability)BaseApplication.php +6 moreHigh
JP3-0054PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)iterator.phpHigh
JP3-0055PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)iterator.phpHigh
JP3-0056PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)DataSet.phpHigh
JP3-0057PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)Input.phpHigh

CVE identifiers link to their official record in the National Vulnerability Database (NVD).

Want these fixed on your site?

This is the same dataset behind our Joomla! 3 Security Patch: a one-click Scan & Apply tool that fixes all 50 of these on your own installation.

Get the Security Patch · $19.90