CVE-2025-22213: Joomla! Project Joomla! CMS

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions.

Affected products

  • Joomla! Project Joomla! CMS: version 4.0.0-4.4.11 only; version 5.0.0-5.2.4 only

Published 2025-03-11. Last modified 2026-06-17.