CVE-2008-6299
Joomla < 1.5.7 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
References (7)
Scores
EPSS
0.0001
EPSS Percentile
0.5%
Classification
CWE
CWE-79
Status
published
Affected Products (36)
joomla/joomla
< 1.5.7
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
joomla/joomla
... and 21 more
Timeline
Published
Feb 26, 2009
Tracked Since
Feb 18, 2026