An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request.
We have discovered 202,934 live websites that are affected by CVE-2016-9837.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 202,934 live websites (99% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 46 versions ( 45% of all versions) |
| 15,297 websites | |
| 51,659 websites | |
| 15,116 websites | |
| 12,270 websites | |
| 12,209 websites | |
| 11,802 websites | |
| 8,476 websites | |
| 6,609 websites | |
| 6,344 websites | |
| 5,162 websites |
| .com | 50,232 websites |
| .it | 33,806 websites |
| .ru | 12,699 websites |
| .pl | 8,680 websites |
| .org | 6,422 websites |
| .de | 5,950 websites |
| .co.uk | 5,886 websites |
| .nl | 5,854 websites |
| .com.au | 4,724 websites |
| .net | 4,606 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.de | *,*** | ||
| *******.**.ca | *,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** | ||
| ***************.com | **,*** | ||
| *********.com | **,*** | ||
| ************.com | **,*** | ||
| *****.**.uk | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** |