CVE-2016-9081: Joomla!

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

Affected products

  • Joomla! Joomla!: version 3.4.4 only; version 3.4.5 only; version 3.4.6 only; version 3.4.7 only; version 3.4.8 only; version 3.5.0 only; …

Published 2017-01-23. Last modified 2026-06-17.