joomla! vulnerabilities
CVEs whose affected-version data names the joomla! package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-63083Medium· 6.1Lack of output escaping leads to a XSS vector in the pagebreak plugin.
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
▾ Sunlitjoomla · joomla!EPSS 0.21%via NVD
CVE-2025-63082Medium· 6.1Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
▾ Sunlitjoomla · joomla!EPSS 0.21%via NVD