CVE-2022-23795: Joomla!
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
Affected products
- Joomla! Joomla!: from 2.5.0, up to and including 3.10.6; from 4.0.0, up to and including 4.1.0
Published 2022-03-30. Last modified 2026-06-17.