CVE-2013-3056: Joomla!

Medium severity, CVSS 4.0. EPSS: 1.6% chance of exploitation in the next 30 days.

Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and delete the private messages of arbitrary users via unspecified vectors.

Affected products

  • Joomla! Joomla!: version 2.5.0 only; version 2.5.1 only; version 2.5.2 only; version 2.5.3 only; version 2.5.4 only; version 2.5.5 only; …

Published 2013-05-03. Last modified 2026-06-16.