CVE-2023-23754: Joomla!

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

Affected products

  • Joomla! Joomla!: from 4.2.0, before 4.3.2 (fixed in 4.3.2)

Published 2023-05-30. Last modified 2026-06-17.