Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

Joomla CVE index

All 373 CVE-numbered vulnerabilities mySites.guru tracks across 192 Joomla extensions, grouped by year.

Each record has its own page with the affected version ranges, the rules we match against, and, where we found the flaw ourselves, the write-up we published once the developer had shipped a fix. Years come from the CVE id, so they show when the id was assigned rather than when the flaw reached the extension.

A list like this shows which Joomla extensions have a history. It will not tell you whether the sites you look after are running an affected version right now, and past a handful of sites that is not a question you answer by hand. The mySites.guru subscription answers it: each audit checks every connected site against all 307 rules behind this index and flags the ones that match, with the version to update to.

Subscribe by RSS

One item per CVE as it is added, deduplicated across the rules that reference it.

https://mysites.guru/vulnerabilities/cve/rss.xml

One item per rule instead

Showing all 373 CVEs.

2026

2025

2024

2023

2022

2020

2019

2018

2017

2015

2014

2013

Why no WordPress CVE or vulnerability data?

WordPress is covered by the service too: mySites.guru integrates Wordfence's vulnerability feed in full, mirroring the data published on Wordfence's vulnerability pages, and every connected WordPress site is checked against it on each audit. To research a WordPress plugin or theme yourself, search Wordfence's database directly.