joomla/filter
Joomla Framework Filter Package
Activity
- Latest release
- 1mo ago
- Total releases
- 49
- Cadence
- ~41 days
- Last 12 months
- 3
Reach
- Stars
- 15
Details
- License
- unknown
- First release
- Jul 11, 2013
| Version | Released | |
|---|---|---|
4.1.0
minor
| ||
3.0.6
patch
| ||
4.0.2
patch
| ||
2.0.6
patch
| ||
3.0.5
patch
| ||
4.0.1
patch
| ||
4.0.0
major
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
3.0.4
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
3.0.3
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
3.0.2
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.7
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.6
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.5
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
2.0.0
major
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta5
pre
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.3
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta4
pre
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.2
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta3
pre
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.1
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta2
pre
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.4.0
minor
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
2.0.0-beta
pre
1 CVE
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev | ||
1.3.5
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.3.4
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.3.3
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.3.2
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.3.1
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.3.0
minor
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.6
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.5
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.4
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.3
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.2
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.1
patch
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0
initial
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-beta3
pre
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-beta2
pre
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-beta
pre
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev | ||
1.0-alpha
pre
2 CVEs
CVE-2025-54476
GHSA-fm22-g2q9-j3pw
Sep 30, 2025
Joomla! CMS vulnerable to XSS via the input filter
Medium
Network
Low
High
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class. Affected versions
4.0.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
+ 33 more Show less
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
2.0.0
2.0.0-beta
2.0.0-beta2
2.0.0-beta3
2.0.0-beta4
2.0.0-beta5
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
Fixed in
2.0.6
3.0.5
4.0.1
References
Updated Oct 01, 2025 · Source: OSV.dev
CVE-2022-23800
GHSA-qcv6-h33g-hvrc
BIT-joomla-2022-23800
Mar 31, 2022
Cross-site Scripting (XSS) within joomla/filter class
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. Affected versions
1.0
1.0-alpha
1.0-beta
1.0-beta2
1.0-beta3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
+ 12 more Show less
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
Fixed in
1.4.4
2.0.1
References
Updated Apr 03, 2025 · Source: OSV.dev |