CVE-2012-2901
Joomla JCE <2.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.
References (5)
Scores
EPSS
0.0036
EPSS Percentile
57.6%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
ryan_demmer/joomla_content_editor
< 2.0.21
ryan_demmer/joomla_content_editor
n/a/n/a
Timeline
Published
May 21, 2012
Tracked Since
Feb 18, 2026