Hey everyone,
Over at htprotect.org/joomla-vel-feed there’s something new: a merge of the National Vulnerability Database (NVD) feed with the HTProtect definitions feed.
The NVD site provides all the security vulnerabilities published by the Joomla project as a CNA – covering both the core and third-party extensions. The HTProtect feed shows what’s covered, split into two categories:
- Warning – the extension is on the warning list. Affected sites get a heads-up in the component and dashboard, including the version that fixes the vulnerability. If auto-updates are enabled, HTProtect will trigger the update automatically.
- Firewall – there’s a signature for this attack vector. It gets blocked before the update is applied.
As of today, there are 394 entries, with 155 warnings and 14 having their own firewall rule. The 14 specific rules are counted conservatively – only those directly linked to a CVE. Generic rules like the upload filter and the .htaccess shield catch a lot more, but those can’t be neatly assigned individually.
Other features of the site:
- Search by CVE ID, extension, and vendor
- Filter by severity (multiple selections possible), core/extension, and coverage
- Light and dark mode, initially matching your system settings
- Available in German and English
- RSS-Feed to subscribe – no account or email needed
The site keeps itself up to date: vulnerability data is refreshed multiple times daily from the NVD, and HTProtect coverage is also updated automatically.
If you notice anything missing or off: just shout.
Cheers
Pascal