JoomScan is the vulnerability scanner for the Joomla sites included in Kali Linux. To use it, you only need to add the -u option followed by the site's URL as follows:
joomscan -u http://10.7.7.5/joomla
JoomScan first tries to fingerprint the server by detecting the Joomla version and plugin, as shown in the following screenshot:
After that, JoomScan will show the vulnerabilities related to the detected configuration or installed plugins: