CVE-2018-11326Cross-site Scripting in Joomla !

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 83.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 22
Latest updateMay 14

Description

An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

NVDjoomla/joomla_!< 3.8.8
Packagistjoomla/joomla-cms3.0.03.8.8

🔴Vulnerability Details

3
GHSA
Joomla! XSS Vulnerability2022-05-14
OSV
Joomla! XSS Vulnerability2022-05-14
CVEList
CVE-2018-11326: An issue was discovered in Joomla! Core before 32018-05-22
CVE-2018-11326 — Cross-site Scripting in Joomla ! | cvebase