CVE-2018-17855: Joomla!

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.

Affected products

  • Joomla! Joomla!: from 1.5.0, before 3.8.13 (fixed in 3.8.13)

Published 2018-10-09. Last modified 2026-06-17.