CVE-2025-22207: Joomla! Project Joomla! CMS

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.

Affected products

  • Joomla! Project Joomla! CMS: version 4.1.0-4.4.10 only; version 5.0.0-5.2.3 only

Published 2025-02-18. Last modified 2026-06-17.