PT-2026-1462 · Joomla+2 · Joomla! Cms+1

Sho Sugiyama

·

Published

2026-01-06

·

Updated

2026-01-31

·

CVE-2025-63082

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions versions prior to 2025 (affected versions not specified)
Description A flaw exists due to insufficient input validation, resulting in a cross-site scripting (XSS) vector within the HTML filter code. This issue specifically relates to data URLs found within img tags. The vulnerability allows for the injection of malicious scripts through crafted image tags.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2025-63082
CVE-2025-63082

Affected Products

Joomla! Cms
Joomla!