← Vulnerability feed

Vulnerability record · CVE-2021-26030 · published 14 April 2021

CVE-2021-26030: Joomla core error page logo parameter XSS via inadequate escaping

Joomla · Joomla\!

Joomla 3.0.0 through 3.9.25 fails to properly escape the logo parameter used by default templates on error pages, allowing reflected cross-site scripting. Because the flaw sits in core error handling, any site running an affected release is exposed without extra components.

6.1 CVSS 3.1 Medium EPSS 82% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS rates it medium (6.1) and it requires user interaction, but the high EPSS score and unauthenticated network vector raise the practical risk for unpatched Joomla sites.

What it is

Joomla 3.0.0 through 3.9.25 fails to properly escape the logo parameter used by default templates on error pages, allowing reflected cross-site scripting. Because the flaw sits in core error handling, any site running an affected release is exposed without extra components.

Impact

An attacker can execute script in the context of the victim's browser session, enabling session theft, credential phishing or page manipulation on the affected Joomla site.

Attack surface

Reached over the network through a crafted request to an error page carrying a malicious logo parameter; no authentication is required, but the victim must be induced to load the crafted URL (UI:R).

Exploitation

Not listed in CISA KEV and no public exploit references are tagged beyond the vendor advisory, though EPSS is high at 0.82 (99.6th percentile), indicating elevated predicted exploitation activity.

What to do

  • Upgrade Joomla to a release after 3.9.25 that contains the fix from the April 2021 security centre advisory.
  • If immediate upgrade is not possible, restrict or filter the logo parameter on error pages at the web server or WAF.
  • Deploy a content security policy that blocks inline and untrusted script execution to reduce XSS impact.
  • Review and harden error page templates so user-supplied parameters are escaped before output.

Detection

  • Search web and WAF logs for requests to Joomla error pages containing script-like payloads in the logo parameter.
  • Monitor for reflected script content in error page responses, especially encoded or obfuscated payloads.
  • Alert on outbound requests or session anomalies originating from users who recently hit crafted error page URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-26030 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed9.8CVE-2026-48902Joomla\! cleartext transmission vulnerabilityThe password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.EPSS 0.33%9.8CVE-2025-25226Joomla\! sql injection vulnerabilityImproper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …EPSS 0.47%9.8CVE-2022-23795Joomla\! improper authentication vulnerabilityAn issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …EPSS 1.1%9.8CVE-2022-23797Joomla\! sql injection vulnerabilityAn issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted …EPSS 1.1%9.8CVE-2022-23799Joomla\! vulnerabilityAn issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.EPSS 1.2%9.8CVE-2010-1433Joomla\! unrestricted file upload vulnerabilityJoomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-26030), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.