Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Joomla:
>> Joomla!
>> 4.0.5
Security Vulnerabilities
CVE-2026-21631
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-04-01
CVE-2026-21632
Lack of output escaping for article titles leads to XSS vectors in various locations.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-04-01
CVE-2026-23898
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
CVSS Score
8.6
EPSS Score
0.0
Published
2026-04-01
CVE-2026-23899
An improper access check allows unauthorized access to webservice endpoints.
CVSS Score
8.6
EPSS Score
0.0
Published
2026-04-01
CVE-2026-21629
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
CVSS Score
6.3
EPSS Score
0.0
Published
2026-04-01
CVE-2026-21630
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-04-01
CVE-2025-63082
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-01-06
CVE-2025-63083
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-01-06
CVE-2025-25227
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-04-08
CVE-2024-40747
Various module chromes didn't properly process inputs, leading to XSS vectors.
CVSS Score
6.1
EPSS Score
0.001
Published
2025-01-07
Next
Page 1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved