Medium severity6.1NVD Advisory· Published Jun 2, 2020· Updated Jun 17, 2026
CVE-2020-13761
CVE-2020-13761
Description
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*range: >=3.0.1,<3.9.19
- cpe:2.3:a:joomla:joomla\!:3.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:joomla:joomla\!:3.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:joomla:joomla\!:3.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:joomla:joomla\!:3.0.0:beta1:*:*:*:*:*:*
- Joomla!/Joomla!description
- Range: <3.9.19
- Range: <3.9.19
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.