Description
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
Remediation
References
Related Vulnerabilities
Plone CMS CVE-2024-23756 Vulnerability (CVE-2024-23756)
WordPress Plugin CYSTEME Finder, the admin files explorer Cross-Site Request Forgery (1.4)
WordPress 5.1.x PHP Object Injection (5.1 - 5.1.9)
MySQL Other Vulnerability (CVE-2005-2572)
WordPress Plugin WP Import Export Lite Security Bypass (3.9.4)