CVE-2023-23755: Joomla!

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

Affected products

  • Joomla! Joomla!: from 4.2.0, before 4.3.2 (fixed in 4.3.2)

Published 2023-05-30. Last modified 2026-06-17.