logo

Joomla! patches XSS flaws that could lead to remote code execution

ID: ab0a435b-ab38-5a91-bf74-9236753dbe22

STIX ID: report--ab0a435b-ab38-5a91-bf74-9236753dbe22

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2024-02-23

Date Updated: 2026-04-28

...
...

Joomla released security updates addressing five vulnerabilities (CVE-2024-21722–CVE-2024-21726) impacting the CMS and framework—issues include improper MFA session termination, open redirect, multiple XSS flaws (some enabling RCE when an admin is tricked), and insufficient input/escaping in components; administrators are urged to upgrade to 3.10.15-elts, 4.4.3, or 5.0.3 and follow CMS hardening practices (minimal extensions, 2FA, WAF, restricted uploads).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.