CVE-2025-63082

EPSS 0.00%

Joomla! Core - [20260101] - Inadequate content filtering for data URLs

Published: 1/31/2026Modified: 1/31/2026

Description

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

References (2)