CVE-2018-17859: Joomla!

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.

Affected products

  • Joomla! Joomla!: from 2.5.0, before 3.8.13 (fixed in 3.8.13)

Published 2018-10-09. Last modified 2026-06-17.