CVE-2017-7986: Joomla!
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
Affected products
- Joomla! Joomla!: version 1.5.0 only; version 1.5.1 only; version 1.5.2 only; version 1.5.3 only; version 1.5.4 only; version 1.5.5 only; …
Published 2017-04-25. Last modified 2026-06-17.