← Vulnerability feed

Vulnerability record · CVE-2021-23124 · published 12 January 2021

CVE-2021-23124: Joomla mod_breadcrumbs aria-label attribute XSS

Joomla · Joomla\!

Joomla! 3.9.0 through 3.9.23 fails to escape the aria-label attribute in the mod_breadcrumbs module, allowing cross-site scripting. The flaw is remotely reachable and can execute script in a victim's browser session, which matters for any site running an affected version.

6.1 CVSS 3.1 Medium EPSS 79% · top 0.4% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is a remotely reachable XSS with a high EPSS score and a broad affected version range, though it requires user interaction and is not in KEV.

What it is

Joomla! 3.9.0 through 3.9.23 fails to escape the aria-label attribute in the mod_breadcrumbs module, allowing cross-site scripting. The flaw is remotely reachable and can execute script in a victim's browser session, which matters for any site running an affected version.

Impact

An attacker can run arbitrary script in the context of the victim's browser, enabling session theft, credential capture or page defacement within the Joomla site.

Attack surface

Reached over the network through the breadcrumbs module output; the CVSS vector shows no privileges required but user interaction is required, so a victim must visit a crafted page or link.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged beyond the vendor advisory, but EPSS is high at 0.7896 (99.57th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Joomla! to a version later than 3.9.23 that contains the fix from the January 2021 security release.
  • If immediate upgrade is not possible, disable or remove the mod_breadcrumbs module until patched.
  • Apply output escaping or a WAF rule that blocks script injection in the aria-label parameter.
  • Review and harden any custom templates that override mod_breadcrumbs output.
  • Monitor the vendor security centre advisory for the official patch guidance.

Detection

  • Search web and proxy logs for requests containing script tags or event handlers in breadcrumbs-related parameters.
  • Inspect mod_breadcrumbs rendered output for unescaped aria-label values.
  • Alert on anomalous JavaScript execution or DOM changes on pages that include the breadcrumbs module.
  • Correlate Joomla version inventory to flag sites still running 3.9.0 through 3.9.23.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed9.8CVE-2026-48902Joomla\! cleartext transmission vulnerabilityThe password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.EPSS 0.33%9.8CVE-2025-25226Joomla\! sql injection vulnerabilityImproper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …EPSS 0.47%9.8CVE-2022-23795Joomla\! improper authentication vulnerabilityAn issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …EPSS 1.1%9.8CVE-2022-23797Joomla\! sql injection vulnerabilityAn issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted …EPSS 1.1%9.8CVE-2022-23799Joomla\! vulnerabilityAn issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.EPSS 1.2%9.8CVE-2010-1433Joomla\! unrestricted file upload vulnerabilityJoomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-23124), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.