Critical severity9.8OSV Advisory· Published May 22, 2018· Updated Jun 17, 2026
CVE-2018-11325
CVE-2018-11325
Description
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/104278nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040966nvdThird Party AdvisoryVDB Entry
- developer.joomla.org/security-centre/732-20180504-core-installer-leaks-plain-text-password-to-local-user.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.