CVE-2019-16725: Joomla!

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.

Affected products

  • Joomla! Joomla!: from 3.0.0, before 3.9.12 (fixed in 3.9.12)

Published 2019-09-24. Last modified 2026-06-17.