VYPR
Medium severity6.1NVD Advisory· Published Jun 11, 2019· Updated Jun 17, 2026

CVE-2019-12766

CVE-2019-12766

Description

An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Joomla/Joomla!2 versions
    cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*range: >=3.6.0,<=3.9.6
    • (no CPE)range: <3.9.7
  • Joomla!/Joomla!description

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.