CVE-2025-54477: Joomla! Project Joomla! CMS

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.

Affected products

  • Joomla! Project Joomla! CMS: version 4.0.0-4.4.13 only; version 5.0.0-5.3.3 only

Published 2025-09-30. Last modified 2026-06-17.