CVE-2026-35220
Joomla! Core - [20260505] - CSRF in user activation endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
| CWE | CWE-352 |
| Vendor | joomla! project |
| Product | joomla! cms |
| Published | May 26, 2026 |
| Last Updated | May 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomla! project joomla! cms
Be the first to know when new unknown vulnerabilities affecting joomla! project joomla! cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Joomla! Project / Joomla! CMS
6.0.0-6.1.0
References
Credits
Sun HuangnSec