logo

Joomla XSS Bugs Open Millions of Websites to RCE

ID: 933b66ca-b47d-54be-b9ef-0d4adc592da0

STIX ID: report--933b66ca-b47d-54be-b9ef-0d4adc592da0

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-02-20

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Joomla's core filter component contains multiple XSS vulnerabilities (CVE-2024-21726) that can enable injection of malicious scripts and may lead to remote code execution when an administrator is lured to click a crafted link; patches are available in Joomla 5.0.3 and 4.4.3 and users should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.