CVE-2026-35222
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
| CWE | CWE-89 |
| Vendor | joomla! project |
| Product | joomla! cms |
| Published | May 26, 2026 |
| Last Updated | Jun 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomla! project joomla! cms
Be the first to know when new unknown vulnerabilities affecting joomla! project joomla! cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Joomla! Project / Joomla! CMS
6.0.0-6.1.0 4.0.0-5.4.5
References
Credits
Adrian Junge aka vurlo Federico Brasili, https://www.linkedin.com/in/federico-brasili-00b4b7332/