CVE-2021-26032
An issue was discovered in Joomla!
MEDIUM
Joomla CMS
Source officielle
Description
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
Sévérité
6.1
Moyenne · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.1 (v3.1) |
| CERT-FR (ANSSI) | — | — |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- Non précisée
- Publiée
- 26/05/2021
- Modifiée
- 17/06/2026
- CWE
- CWE-79
Versions concernées
- 3.0.0 – 3.9.26
Sources
- NVD CNA Joomla CVE-2021-26032 vu
- CERT-FR (ANSSI) Avis vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Source ajoutée : nvd26/09/2026 09:34 UTC
- Détectée via certfr26/09/2026 09:28 UTC