CVE-2019-10945: Joomla!

Critical severity, CVSS 9.8. EPSS: 38% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.

Affected products

  • Joomla! Joomla!: from 1.5.0, up to and including 3.9.4

Published 2019-04-10. Last modified 2026-06-17.