CVE-2018-11322: Joomla!

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.

Affected products

  • Joomla! Joomla!: before 3.8.8 (fixed in 3.8.8)

Published 2018-05-22. Last modified 2026-06-17.