CVE-2025-63082

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/01/2026
Last modified:
30/01/2026

Description

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* 4.0.0 (including) 5.4.2 (excluding)
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.2 (excluding)