SEO & Website Marketing

Joomla sites hacked

Estimate: Joomla sites hacked but undiscovered

There is no global census. This estimate uses live-site counts, version mix, and the few Joomla-specific infection rates that exist.

How many Joomla sites there are

Live crawls and market-share numbers disagree, but they sit in the same order of magnitude:

  • webatla (8 Sep 2026): 528,311 live Joomla sites.
  • WebTechSurvey: ~650,000 live sites.
  • W3Techs (Sep 2026): Joomla is 1.1% of all websites and 1.7% of known CMS sites. Applied to the whole web that is often rounded to around a million properties.

The useful base for “hacked and still running” is live sites: about 0.5–1.0 million.

The version mix is the security story. W3Techs reports 52.6% still on Joomla 3, with 20.6% on 5, 8.4% on 4, 8.1% on 6, and the rest on 1.x/2.x. Joomla 3 has had no official core security patches since August 2023.

How often those sites are actually compromised

Unlike WordPress, there is no Wordfence-scale public infection census. The best measured rates come from mySites.guru, which monitors paid/cared-for Joomla sites (so this is a lower bound for neglected sites):

Branch
Currently flagged hacked
Joomla 3
4.90%
Joomla 4
4.67%
Joomla 5
2.67%
Joomla 6
0.98%


A Joomla 3 site in that sample is about as likely to be compromised as a Joomla 6 site. They also note they find 200+ hacked Joomla sites a week in routine audits, and that most Joomla hacks are invisible to the owner.

Weighting those rates by the public version mix gives a rough point-in-time infection rate of ~3–5% on monitored sites. Abandoned 1.x/2.x/old 3.x sites, which crawlers still see in large numbers, will sit higher.

2026 also had repeated mass-exploitation waves in popular extensions (JCE, Helix3, SP Page Builder, Page Builder CK, iCagenda, Balbooa Forms). Several were unauthenticated RCE, added to CISA’s KEV list, and described as hitting hundreds to thousands of sites in days. Patching closes the hole; it does not remove a backdoor already planted.

A defensible stock of currently compromised live Joomla sites is therefore about 15,000–60,000 (midpoint ~25,000–40,000), not hundreds of thousands.

How many owners still do not know

Same detection lag as other small-CMS sites, and Joomla is more neglected:

  • Many installs are old agency hand-offs or government/club sites that nobody patches.
  • Payloads are often SEO spam, conditional redirects, extra Super Users, or database-only template injections that file scanners miss. The Helix3 wave is a concrete example: homepage defacement lived in the database; disk scanners came back clean.
  • Business-site studies (not Joomla-only) found ~82% of owners took more than a month to notice and ~44% took 3+ months.

On Joomla, a fair split of current infections is:

  • 15–35% already known or about to be (host, Google, agency monitor)
  • 65–85% still unknown to the owner

That is a bit worse than WordPress because so much of the estate is end-of-life and unmonitored.

Estimate

For live Joomla sites right now:

Piece Low Mid High
Currently compromised 15,000 30,000 60,000
Owner still unaware ~10,000 ~20,000–25,000 ~50,000


Best single estimate: on the order of 20,000–30,000 Joomla sites are compromised today without the owner knowing.

If you include barely maintained and abandoned installs that still answer HTTP, the “hacked and nobody is looking” pool can stretch toward ~40,000–70,000. It does not reach WordPress scale. Joomla is roughly 1/50th to 1/70th the size of the live WordPress web, and the infection rate is higher because of EOL cores, but the absolute number of quiet hacks is still tens of thousands, not hundreds of thousands.

Why this is fuzzier than the WordPress estimate

  • No vendor publishes a yearly “N Joomla sites infected.”
  • The best hacked-rate data is from sites already being monitored, which understates the abandoned tail.
  • “Hacked” here mixes webshells, extra Super Users, SEO spam, and database-only defacements.
  • Summer 2026 extension RCEs mean the stock can jump by thousands in a week, then sit undiscovered for months.

So: not a rounding error, and not a WordPress-sized underground. For living Joomla sites, low tens of thousands of quiet compromises is the most honest current estimate.