com_contact
by Joomla
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-6261 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2019 | An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability. | ||
| CVE-2019-15028 | Med | 0.35 | 5.3 | 0.01 | Aug 14, 2019 | In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms. | ||
| CVE-2026-48948 | 0.00 | — | 0.00 | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.
- risk 0.35cvss 5.3epss 0.01
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
- CVE-2026-48948Jul 7, 2026risk 0.00cvss —epss 0.00
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.