CVE-2016-8869: Joomla!
Critical severity, CVSS 9.8. EPSS: 97.3% chance of exploitation in the next 30 days.
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
Affected products
- Joomla! Joomla!: up to and including 3.6.3
Published 2016-11-04. Last modified 2026-06-17.