CVE-2020-10243: Joomla!

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.

Affected products

  • Joomla! Joomla!: from 1.7.0, before 3.9.16 (fixed in 3.9.16)

Published 2020-03-16. Last modified 2026-06-17.