Showing 2 vulnerabilities on this page for joomla\!

Signals CISA KEV Ransomware Nuclei
Joomla vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

[20240804] - Core - Improper ACL for backend profile view

Improper Access Controls allows backend users to overwrite their username when disallowed.

CWE-284Aug 20, 2024
CVSS7.5v3.1EPSS0.354%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

[20230201] - Core - Improper access check in webservice endpoints

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

CWE-284Feb 16, 20231 related artifact
CVSS5.3v3.1EPSS99.8%PoCs51SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX