CVE-2021-26032

All FrameworksJoomlaCWE-OtherCVE-2021-26032

CVE-2021-26032

State: PUBLISHED · Published: 2021-05-26 · Updated: 2026-02-25 · Assigner: Joomla
Description
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/26xxx/CVE-2021-26032.json