CVE-2018-6378: Joomla!

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.

Affected products

  • Joomla! Joomla!: before 3.8.8 (fixed in 3.8.8)

Published 2018-05-22. Last modified 2026-06-17.