CVE-2026-35221
Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
| CWE | CWE-89 |
| Vendor | joomla! project |
| Product | joomla! cms |
| Published | May 26, 2026 |
| Last Updated | May 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomla! project joomla! cms
Be the first to know when new unknown vulnerabilities affecting joomla! project joomla! cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Joomla! Project / Joomla! CMS
6.0.0-6.1.0 5.4.0-5.4.5
References
Credits
Adrian Junge aka vurlo