[UPDATE] [medium] Joomla: Multiple vulnerabilities
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Joomla to present false information, launch a Cross-Site Scripting attack, and modify data.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote attackers to present false information, launch XSS attacks, and modify data.
- Who is affected
- All deployments of Joomla are at risk.
- Urgency
- Medium urgency for remediation due to the potential for data manipulation.
- Action
- Update Joomla to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Joomla
Get an email when a new Joomla advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1891
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2024-271850.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-271840.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-271860.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-271870.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-407430.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-27185 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-27184 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-27186 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-27187 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-40743 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Joomla
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-77998: Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Par…nvd · 2026-08-25
- unknownCVE-2026-77997: Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme…nvd · 2026-08-25
- unknownCVE-2026-77996: Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5…nvd · 2026-08-25
- unknownCVE-2026-77995: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.…nvd · 2026-08-24
- unknownCVE-2026-77994: Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The J…nvd · 2026-08-24
- unknownCVE-2026-77993: Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extensi…nvd · 2026-08-24
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25