CVE-2017-16634: Joomla!

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

Affected products

  • Joomla! Joomla!: from 3.2.0, up to and including 3.8.1

Published 2017-11-10. Last modified 2026-06-17.