CVE-2017-7987: Joomla!

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.

Affected products

  • Joomla! Joomla!: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.3.0 only; …

Published 2017-04-25. Last modified 2026-06-17.