CVE-2023-23752: Joomla! Improper Access Control Vulnerability
Medium severity, CVSS 5.3. Actively exploited: in CISA KEV since 2024-01-08. EPSS: 99.8% chance of exploitation in the next 30 days.
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Affected products
- Joomla! Joomla!: from 4.0.0, before 4.2.8 (fixed in 4.2.8)
Published 2023-02-16. Last modified 2026-06-17.