CVE-2018-8045: Joomla!

High severity, CVSS 8.8. EPSS: 28.2% chance of exploitation in the next 30 days.

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

Affected products

  • Joomla! Joomla!: from 3.5.0, up to and including 3.8.5

Published 2018-03-15. Last modified 2026-06-17.