The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
2024-08-20T16:15:10.893
2025-06-04T20:58:35.960
Analyzed
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | joomla | joomla\! | < 4.4.7 | Yes |
Application | joomla | joomla\! | < 5.1.3 | Yes |