
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63082 is a Cross-Site Scripting (XSS) vulnerability in Joomla! CMS caused by inadequate content filtering for data URLs in img tags. The flaw exists in Joomla!'s HTML filter code, which fails to properly sanitize data URLs, allowing attackers to inject malicious scripts. Affected versions include Joomla! 4.0.0 through 5.4.1 and 6.0.0 through 6.0.1. The CVE was published on January 6, 2026, with NVD initial analysis completed January 30, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 score of 5.9 (Medium) (Joomla Advisory, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically arising from insufficient input filtering in Joomla!'s HTML content filter component. The vulnerability allows malicious data: URLs embedded within <img> tags to bypass the HTML sanitization layer, enabling script execution in the victim's browser context. Exploitation requires user interaction (a victim must view or interact with the malicious content) and the attack vector is network-based. The changed scope in the CVSS v3.1 vector indicates the impact can extend beyond the vulnerable component itself (Joomla Advisory, Red Hat CVE).
Successful exploitation could allow an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session hijacking, credential theft, and unauthorized actions on behalf of the affected user. The changed scope in the CVSS scoring indicates that the impact can cross security boundaries, potentially affecting other users or components beyond the directly targeted session. Confidentiality and integrity are both impacted at a low level per CVSS v3.1, while the CVSS v4.0 assessment rates vulnerability-level confidentiality and integrity impacts as high (Joomla Advisory, Red Hat CVE).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.043%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Joomla Advisory, Red Hat CVE).
<img> tag using a data: URL scheme that embeds JavaScript, for example: <img src="data:text/html,<script>alert(document.cookie)</script>">.<img> tag into a content field that passes through Joomla!'s HTML filter (e.g., an article body, a comment, or a custom HTML field), exploiting the lack of filtering for data URLs./administrator/index.php?option=com_content) containing data: URL schemes within img tag parameters.data:text/html or data:application/javascript strings in content fields; error logs indicating HTML filter bypass attempts.<img src="data: patterns.Joomla! has released patched versions addressing this vulnerability: upgrade to 5.4.2 or later for 5.x installations, or 6.0.2 or later for 6.x installations. As a complementary measure, administrators should implement Content Security Policy (CSP) headers to restrict script execution sources, which can help mitigate XSS impact even if a bypass occurs. Additionally, review and restrict user permissions for content creation and HTML editing capabilities to limit the attack surface. Patches are available through the Joomla! Security Centre (Joomla Advisory).
Red Hat has tracked this vulnerability in their security advisory database, indicating awareness among enterprise Linux ecosystem stakeholders (Red Hat CVE). Tenable has published detection plugins for both pipeline and web application scanning (Tenable WAS). No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."