← Vulnerability feed

Vulnerability record · CVE-2018-6377 · published 30 January 2018

CVE-2018-6377: Joomla com_fields input filtering flaw enables stored XSS

Joomla · Joomla\!

Joomla before 3.8.4 fails to filter input adequately in the com_fields component, allowing cross-site scripting through the list, radio and checkbox field types. Because custom fields are commonly rendered on public pages, injected script can run in the browser of any visitor viewing the affected field.

6.1 CVSS 3.0 Medium EPSS 57% · top 1.0% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable with no privileges and a high EPSS score, though it requires user interaction and no known exploitation is confirmed.

What it is

Joomla before 3.8.4 fails to filter input adequately in the com_fields component, allowing cross-site scripting through the list, radio and checkbox field types. Because custom fields are commonly rendered on public pages, injected script can run in the browser of any visitor viewing the affected field.

Impact

An attacker can execute arbitrary script in a victim's browser session, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change indicates the compromise can extend beyond the vulnerable component.

Attack surface

Reached over the network through the com_fields component; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must view or interact with the crafted field content.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is 0.565 (99th percentile), indicating elevated predicted exploitation activity.

What to do

  • Upgrade Joomla to 3.8.4 or later, which fixes the com_fields filtering issue.
  • If immediate upgrade is not possible, restrict who can create or edit custom fields and review existing field definitions for injected markup.
  • Apply output encoding or sanitization to custom field values rendered in templates.
  • Deploy a web application firewall rule to block script payloads in com_fields parameters as a temporary control.

Detection

  • Search Joomla custom field configuration and content for script tags, event handlers, or javascript: URIs in list, radio and checkbox values.
  • Review web server and application logs for requests to com_fields endpoints containing encoded script payloads.
  • Monitor for unexpected administrator or session activity originating from pages that render custom fields.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6377 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed9.8CVE-2026-48902Joomla\! cleartext transmission vulnerabilityThe password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.EPSS 0.33%9.8CVE-2025-25226Joomla\! sql injection vulnerabilityImproper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …EPSS 0.47%9.8CVE-2022-23795Joomla\! improper authentication vulnerabilityAn issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …EPSS 1.1%9.8CVE-2022-23797Joomla\! sql injection vulnerabilityAn issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted …EPSS 1.1%9.8CVE-2022-23799Joomla\! vulnerabilityAn issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.EPSS 1.2%9.8CVE-2010-1433Joomla\! unrestricted file upload vulnerabilityJoomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-6377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.