logo

Joomla fixes XSS flaws that could expose sites to RCE attacks

ID: 059e88ef-4924-5cf1-840a-c8bdc18b794c

STIX ID: report--059e88ef-4924-5cf1-840a-c8bdc18b794c

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-02-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Joomla released security updates (5.0.3 and 4.4.3) addressing five vulnerabilities — CVE-2024-21722 through CVE-2024-21726 — including XSS flaws, an open redirect, and insufficient MFA session termination. CVE-2024-21725 is flagged as the highest-severity issue with high exploitation probability, while CVE-2024-21726 (an XSS in the core filter) could be chained to achieve remote code execution by tricking an administrator; administrators are urged to apply the available updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.