Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY136 SECURITY RECORDS

Joomla! Project

Joomla! CMS

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-90915 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92226 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92224 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90907 29 Sep 2026 Joomla! CMS: 1.5.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90914 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92231 29 Sep 2026 Joomla! CMS: 1.5.0-5.4.8, 6.0.0-6.1.3; Joomla! Framework Filter package: 1.0.0-3.0.6, 4.0.0-4.1.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90918 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92222 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92223 29 Sep 2026 Joomla! CMS: 5.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90917 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92225 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92227 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-92232 29 Sep 2026 Joomla! CMS: 1.5.0-5.4.8, 6.0.0-6.1.3; Joomla! Framework Filter package: 1.0.0-3.0.6, 4.0.0-4.1.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90916 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90913 29 Sep 2026 Joomla! CMS: 4.0.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-90906 29 Sep 2026 Joomla! CMS: 1.5.0-5.4.8, 6.0.0-6.1.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-71573 18 Aug 2026 4.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-72531 18 Aug 2026 4.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-73336 18 Aug 2026 5.1.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-73372 18 Aug 2026 5.1.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71572 18 Aug 2026 3.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-73337 18 Aug 2026 4.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-73371 18 Aug 2026 4.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-72532 18 Aug 2026 4.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-73373 18 Aug 2026 1.0.0-5.4.6; 6.0.0-6.1.2; 1.0.0-3.3.0; 4.0.0-4.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71574 18 Aug 2026 4.0.0-5.4.6; 6.0.0-6.1.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48952 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48947 7 Jul 2026 4.1.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48958 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48950 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48955 7 Jul 2026 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48956 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48957 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48951 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48953 7 Jul 2026 4.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48948 7 Jul 2026 3.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48949 7 Jul 2026 4.2.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48954 7 Jul 2026 3.0.0-5.4.6; 6.0.0-6.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-35221 26 May 2026 6.0.0-6.1.0; 5.4.0-5.4.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48896 26 May 2026 4.0.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-35220 26 May 2026 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-40383 26 May 2026 3.2.1-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-35222 26 May 2026 6.0.0-6.1.0; 4.0.0-5.4.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-40384 26 May 2026 4.0.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48897 26 May 2026 4.0.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-25901 26 May 2026 4.0.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48899 26 May 2026 4.0.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48900 26 May 2026 4.1.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48902 26 May 2026 3.9.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-35223 26 May 2026 4.0.0-5.4.5; 6.0.0-6.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.