Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/aramosf/joomla_exploits
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed TeamingCrawlerLabs & Practice
GitHubaramosf/joomla_exploits

joomla_exploits

View Repository
11 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Joomla Exploits

This repository contains selected Joomla exploit artifacts validated against real Docker Joomla environments. The collection is split by practical offensive utility.

real-impact

Exploits with direct security impact: RCE, file upload to code execution, SQL injection, sensitive configuration disclosure, arbitrary file deletion, stored XSS against an administrator, or privilege escalation.

OrderCVECVSSTargetExploit script
1CVE-2026-4893910.0iCagenda public event attachment uploadcve_2026_48939_icagenda_real_http_rce.py
2CVE-2026-2162810.0Astroid Framework com_ajax media file managercve_2026_21628_astroid_real_http_rce.py
3CVE-2026-4890710.0JCE com_jce profiles.import profile uploadcve_2026_48907_jce_real_http_rce.py
4CVE-2026-4890810.0SP Page Builder asset.uploadCustomIcon custom icon uploadcve_2026_48908_sppagebuilder_real_http_rce.py
5CVE-2023-237539.8Visforms addSupportedFieldTypecve_2023_23753_visforms_real_http_sqli.py
6CVE-2026-490489.8JoomCCK com_joomcck tags.savecve_2026_49048_joomcck_real_http_sqli.py
7CVE-2025-222049.8Regular Labs Sourcerer alternate PHP syntaxcve_2025_22204_sourcerer_real_http_rce.py
8CVE-2025-268549.8Articles Good Search mod_articles_good_searchcve_2025_26854_articles_good_search_real_http_sqli.py
9CVE-2025-26855

conceptual-pocs

PoCs that demonstrate real vulnerabilities but are less directly useful as standalone intrusion primitives. They are retained for research, chaining, or defensive validation.

Usage

  1. Enter one CVE directory under real-impact/ or conceptual-pocs/.
  2. Start the lab when a docker-compose.yml is present: docker compose up -d.
  3. Read the CVE README.md and, when present, exploits/README.md for setup notes.
  4. Run the exploit script from the CVE directory or pass the target URL explicitly.

No proprietary vulnerable extension ZIPs or Joomla distribution ZIPs are included. Download vulnerable software from the links in each CVE README and test only in authorized local labs.

Unvalidated candidates

Three records that were previously mistaken for public exploits remain gated on unavailable commercial or historical packages. Their exact blockers are documented in unvalidated-candidates and no unvalidated exploit is published for them.

Installation limitations

CVE-2025-54300 and CVE-2025-54301 were validated through real Quantum Manager 3.2.0 HTTP routes in Joomla Docker using unchanged source from official commit 1bf656d. That source package did not complete Joomla's standard installer, so the lab copied the official component files into Joomla and registered its metadata manually. Their directories document this limitation and include the registration SQL; they do not claim a one-command clean installation or redistribute vulnerable packages.

Download Tool
9.8
Articles Calendar mod_articles_calendar
cve_2025_26855_articles_calendar_real_http_sqli.py
10CVE-2024-407449.8Convert Forms com_convertformscve_2024_40744_convert_forms_real_http_upload_rce.py
11CVE-2025-542989.4CommentBox comments.add User-Agentcve_2025_54298_commentbox_real_http_stored_xss.py
12CVE-2026-489069.3Tassos Framework GalleryManager2 deletecve_2026_48906_tassos_real_http_delete.py
13CVE-2025-494679.3JEvents com_jevents range.listevents enddatecve_2025_49467_jevents_real_http_sqli.py
14CVE-2025-544739.2Phoca Commander authenticated unpack actioncve_2025_54473_phoca_commander_real_http_rce.py
15CVE-2025-544758.7JS Jobs employer package purchasecve_2025_54475_jsjobs_real_http_sqli.py
16CVE-2026-238988.6Joomla com_joomlaupdate finalizeUpdate APIcve_2026_23898_joomla_update_api_file_delete.py
17CVE-2026-238998.6Joomla com_config application APIcve_2026_23899_joomla_config_api_access_bypass.py
18CVE-2026-488988.2Joomla com_users batch taskcve_2026_48898_joomla_com_users_batch_privilege_escalation_real_http.py
19CVE-2026-489048.2Joomla com_users groups APIcve_2026_48904_joomla_com_users_group_api_privilege_escalation_real_http.py
OrderCVECVSSTargetExploit script
1CVE-2024-271859.1Joomla core com_content pagination cache handlingcve_2024_27185_joomla_pagination_cache_poison.py
2CVE-2026-489029.8Joomla CMS core com_users reset/remindcve_2026_48902_joomla_reset_link_downgrade.py
3CVE-2026-488968.2Joomla Core MFAcve_2026_48896_joomla_mfa_bypass_real_http.py
4CVE-2026-488978.2Joomla Core MFA session statecve_2026_48897_joomla_mfa_session_state_bypass_real_http.py
5CVE-2026-352238.6Joomla com_config component APIcve_2026_35223_joomla_component_config_api_access_bypass.py
6CVE-2025-543008.5Quantum Manager SVG uploadcve_2025_54300_quantum_manager_real_http_stored_xss.py
7CVE-2025-543018.5Quantum Manager filename renderingcve_2025_54301_quantum_manager_real_http_filename_xss.py