CVE-2018-17856: Joomla!

High severity, CVSS 7.2. EPSS: 2.7% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.

Affected products

  • Joomla! Joomla!: from 2.5.4, before 3.8.13 (fixed in 3.8.13)

Published 2018-10-09. Last modified 2026-06-17.