CVE-2021-26030

MEDIUM

Joomla! 3.0.0-3.9.25 - Cross-Site Scripting via Logo Parameter on Error Page

Title source: llm
STIX 2.1

Description

An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0933
EPSS Percentile 92.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
joomla/joomla\! 3.0.0 - 3.9.25
Published Apr 14, 2021
Tracked Since Feb 18, 2026