🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Web Application Vulnerabilities
This page lists
24302 vulnerabilities
in
62 categories
.
Critical: 1589
High: 13053
Medium: 8721
Low: 870
Information: 69
Vulnerability Name
CVE
CWE
Severity
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21726)
CVE-2024-21726
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21729)
CVE-2024-21729
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21730)
CVE-2024-21730
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21731)
CVE-2024-21731
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-26278)
CVE-2024-26278
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-26279)
CVE-2024-26279
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-27186)
CVE-2024-27186
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-40743)
CVE-2024-40743
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-40747)
CVE-2024-40747
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-40748)
CVE-2024-40748
CWE-707
High
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-63082)
CVE-2025-63082
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-63083)
CVE-2025-63083
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-21631)
CVE-2026-21631
CWE-707
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-21632)
CVE-2026-21632
CWE-707
Medium
Joomla Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2007-4190)
CVE-2007-4190
CWE-138
Medium
Joomla Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2016-10045)
CVE-2016-10045
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') Vulnerability (CVE-2017-14596)
CVE-2017-14596
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2006-1049)
CVE-2006-1049
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-0795)
CVE-2008-0795
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-1935)
CVE-2008-1935
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6852)
CVE-2008-6852
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-1499)
CVE-2009-1499
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-2679)
CVE-2010-2679
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4166)
CVE-2010-4166
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4696)
CVE-2010-4696
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2011-1151)
CVE-2011-1151
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-1116)
CVE-2012-1116
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-7981)
CVE-2014-7981
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-4654)
CVE-2015-4654
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-7297)
CVE-2015-7297
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-7857)
CVE-2015-7857
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-7858)
CVE-2015-7858
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-8769)
CVE-2015-8769
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-8917)
CVE-2017-8917
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-6376)
CVE-2018-6376
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-8045)
CVE-2018-8045
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-19846)
CVE-2019-19846
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-10243)
CVE-2020-10243
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-35613)
CVE-2020-35613
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-23797)
CVE-2022-23797
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-25226)
CVE-2025-25226
CWE-138
Critical
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2026-21630)
CVE-2026-21630
CWE-138
High
Joomla Improper Preservation of Permissions Vulnerability (CVE-2020-13763)
CVE-2020-13763
CWE-281
High
Joomla Improper Privilege Management Vulnerability (CVE-2012-1563)
CVE-2012-1563
CWE-269
High
Joomla Improper Privilege Management Vulnerability (CVE-2018-11323)
CVE-2018-11323
CWE-269
High
Joomla Improper Privilege Management Vulnerability (CVE-2018-17855)
CVE-2018-17855
CWE-269
High
Joomla Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2023-23755)
CVE-2023-23755
CWE-307
High
Joomla Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Vulnerability (CVE-2019-11358)
CVE-2019-11358
CWE-1321
Medium
Joomla Inadequate Encryption Strength Vulnerability (CVE-2011-3629)
CVE-2011-3629
CWE-326
High
Joomla Inadequate Encryption Strength Vulnerability (CVE-2021-23126)
CVE-2021-23126
CWE-326
Medium
Joomla Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2024-27185)
CVE-2024-27185
-
Critical
Joomla Incorrect Authorization Vulnerability (CVE-2010-1435)
CVE-2010-1435
CWE-863
Critical
Joomla Incorrect Authorization Vulnerability (CVE-2018-17857)
CVE-2018-17857
CWE-863
Medium
Joomla Incorrect Authorization Vulnerability (CVE-2020-11889)
CVE-2020-11889
CWE-863
Medium
Joomla Incorrect Authorization Vulnerability (CVE-2020-11891)
CVE-2020-11891
CWE-863
Medium
Joomla Incorrect Authorization Vulnerability (CVE-2021-26027)
CVE-2021-26027
CWE-863
Medium
Joomla Incorrect Authorization Vulnerability (CVE-2023-23751)
CVE-2023-23751
CWE-863
Medium
Joomla Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2011-4912)
CVE-2011-4912
CWE-732
Medium
Joomla Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-15697)
CVE-2020-15697
CWE-732
Medium
Joomla Insufficient Session Expiration Vulnerability (CVE-2021-26037)
CVE-2021-26037
CWE-613
Medium
Joomla Insufficient Session Expiration Vulnerability (CVE-2024-21722)
CVE-2024-21722
CWE-613
Medium
Joomla Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-15699)
CVE-2020-15699
CWE-345
Medium
Joomla J!Dump extension enabled
-
CWE-200
Medium
Joomla Missing Authentication for Critical Function Vulnerability (CVE-2019-10946)
CVE-2019-10946
CWE-306
High
Joomla Missing Authorization Vulnerability (CVE-2019-18674)
CVE-2019-18674
CWE-862
Medium
Joomla Missing Authorization Vulnerability (CVE-2019-9713)
CVE-2019-9713
CWE-862
High
Joomla Missing Authorization Vulnerability (CVE-2020-10239)
CVE-2020-10239
CWE-862
High
Joomla Missing Authorization Vulnerability (CVE-2021-23123)
CVE-2021-23123
CWE-862
Medium
Joomla Numeric Errors Vulnerability (CVE-2008-4102)
CVE-2008-4102
-
High
Joomla Other Vulnerability (CVE-2005-3771)
CVE-2005-3771
-
Medium
Joomla Other Vulnerability (CVE-2005-3772)
CVE-2005-3772
-
High
Joomla Other Vulnerability (CVE-2005-3773)
CVE-2005-3773
-
Critical
Joomla Other Vulnerability (CVE-2006-0303)
CVE-2006-0303
-
Critical
Joomla Other Vulnerability (CVE-2006-1027)
CVE-2006-1027
-
Medium
Joomla Other Vulnerability (CVE-2006-1028)
CVE-2006-1028
-
High
«
1
...
61
62
63
...
325
»