CVE-2025-63082Cross-site Scripting in Joomla !

Severity
5.9MEDIUMNVD
EPSS
0.0%
top 99.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 6

Description

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDjoomla/joomla_!4.0.05.4.2+1
CVEListV5joomla!_project/joomla!_cms4.0.0-5.4.1, 6.0.0-6.0.1+1

🔴Vulnerability Details

2
CVEList
Joomla! Core - [20260101] - Inadequate content filtering for data URLs2026-01-06
GHSA
GHSA-w359-ppwg-hrqh: Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags2026-01-06

🕵️Threat Intelligence

1
Wiz
CVE-2025-63082 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-63082 — Cross-site Scripting in Joomla ! | cvebase