CVE-2025-63082

MEDIUM

Joomla! 4.0.0 through 5.4.2 - Cross-Site Scripting via Data URLs in HTML Filter

Title source: llm
STIX 2.1

Description

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
joomla/joomla\! 4.0.0 - 5.4.2
Published Jan 06, 2026
Tracked Since Feb 18, 2026