Filter Flaw Exposes Custom Fields to Cross-Site Scripting Attacks
CVE-2024-26278
6.1MEDIUM
What is CVE-2024-26278?
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
Affected Version(s)
Joomla! CMS 3.7.0-3.10.15
Joomla! CMS 4.0.0-4.4.5
Joomla! CMS 5.0.0-5.1.1