Medium severity6.1NVD Advisory· Published Jul 10, 2022· Updated Jun 17, 2026
CVE-2022-27910
CVE-2022-27910
Description
In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function
Affected products
4<=3.5.13+ 2 more
- (no CPE)range: <=3.5.13
- cpe:2.3:a:joomlatools:docman:*:*:*:*:*:joomla\!:*:*range: <3.5.14
- (no CPE)range: <=3.5.13
Patches
Vulnerability mechanics
References
1- www.joomlatools.com/extensions/docman/changelog/3.5.14nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.