VYPR
Medium severity6.1OSV Advisory· Published Jun 26, 2018· Updated Jun 17, 2026

CVE-2018-12711

CVE-2018-12711

Description

An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Joomla/Joomla!OSV2 versions
    1.7.3, 2.5.0, 2.5.0_beta1, …+ 1 more
    • (no CPE)range: 1.7.3, 2.5.0, 2.5.0_beta1, …
    • (no CPE)range: >=1.6.0 <=3.8.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.